CVE-2026-27683 PUBLISHED

Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform

Assigner: sap
Reserved: 23.02.2026 Published: 14.04.2026 Updated: 14.04.2026

SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CVSS Score: 4.1

Product Status

Vendor SAP_SE
Product SAP BusinessObjects Business Intelligence Platform
Versions Default: unaffected
  • Version ENTERPRISE 430 is affected
  • Version 2025 is affected
  • Version 2027 is affected

References

Problem Types