Advisory
A note with CVSS 6.1 for component BI-RA-CR was released by SAP on 08.07.2025. The correction/advisory 3617380 was described with "[CVE-2025-42985] Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench" and affects the system type BI/BO platform.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss)open redirect within BI/BO platform.
Risk specification
The SAP BusinessObjects Content Administrator Workbench allows an authenticated attacker to inject malicious URLs, leading to user redirection to harmful sites and potential exposure or modification of web client data.Solution
The vulnerability has been addressed by implementing robust input validation and output encoding within the affected components. All user-supplied URL parameters are now properly sanitized to prevent script injection and unauthorized redirection. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Cross-site scripting/request forgery filter engine on IDS/IPS/firewall systems. ".
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- DW4CORE 100 10
- DW4CORE 200 14
- DW4CORE 300 11
- DW4CORE 400 8
- SAP_BW 700-702 12
- SAP_BW 731 17
- SAP_BW 740 19
- SAP_BW 750-816 5
- SAP_BW_VIRTUAL_COMP 701 6