{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T08:17:28.729","vulnerabilities":[{"cve":{"id":"CVE-2026-24325","sourceIdentifier":"cna@sap.com","published":"2026-02-10T04:16:04.790","lastModified":"2026-02-17T15:14:43.317","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application."},{"lang":"es","value":"SAP BusinessObjects Enterprise no codifica suficientemente las entradas controladas por el usuario, lo que lleva a una vulnerabilidad de cross-site scripting (XSS) almacenado. Esto permite a un usuario administrador inyectar JavaScript malicioso en un sitio web y el script inyectado se ejecuta cuando el usuario visita la página comprometida. Esta vulnerabilidad tiene bajo impacto en la confidencialidad e integridad de los datos. No hay impacto en la disponibilidad de la aplicación."}],"metrics":{"cvssMetricV31":[{"source":"cna@sap.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}]},"weaknesses":[{"source":"cna@sap.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:businessobjects_enterprise:430:*:*:*:*:*:*:*","matchCriteriaId":"0A72BBFB-83AF-444D-8FA1-D93461970A8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:businessobjects_enterprise:2025:*:*:*:*:*:*:*","matchCriteriaId":"5E5C4FE2-06FF-4997-A9AC-3ECC22D86E67"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:businessobjects_enterprise:2027:*:*:*:*:*:*:*","matchCriteriaId":"F9C0B64B-0C14-4297-96D9-85170D17FCBA"}]}]}],"references":[{"url":"https://me.sap.com/notes/3697256","source":"cna@sap.com","tags":["Permissions Required"]},{"url":"https://url.sap/sapsecuritypatchday","source":"cna@sap.com","tags":["Vendor Advisory"]}]}}]}