← Back to CVE List
CVE-2026-27683NVD
Vulnerability Summary
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the userοΏ½s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityNone
AvailabilityNone