VYPR

Businessobjects Business Intelligence

by SAP

CVEs (51)

  • CVE-2023-28765CriApr 11, 2023
    risk 0.65cvss 9.8epss 0.15

    An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the…

  • CVE-2023-40622CriSep 12, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise…

  • CVE-2018-2445CriAug 14, 2018
    risk 0.62cvss 9.6epss 0.01

    AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2023-28762CriMay 9, 2023
    risk 0.59cvss 9.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the…

  • CVE-2022-41203HigNov 8, 2022
    risk 0.57cvss 8.8epss 0.01

    In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to…

  • CVE-2018-2442HigAug 14, 2018
    risk 0.57cvss 8.8epss 0.01

    In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.

  • CVE-2018-2427HigJul 10, 2018
    risk 0.57cvss 8.8epss 0.02

    SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the…

  • CVE-2025-23192HigJun 10, 2025
    risk 0.53cvss 8.2epss 0.00

    SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their browser enabling the attacker to potentially access…

  • CVE-2022-32245HigAug 10, 2022
    risk 0.53cvss 8.2epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and…

  • CVE-2019-0268HigMar 12, 2019
    risk 0.53cvss 8.1epss 0.02

    SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2022-28214HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and…

  • CVE-2024-37179HigOct 8, 2024
    risk 0.50cvss 7.7epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.

  • CVE-2023-37490HigAug 8, 2023
    risk 0.49cvss 7.6epss 0.00

    SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can…

  • CVE-2018-2446HigAug 14, 2018
    risk 0.49cvss 7.5epss 0.02

    Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.

  • CVE-2023-42476MedDec 12, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to…

  • CVE-2023-42474MedOct 10, 2023
    risk 0.44cvss 6.8epss 0.00

    SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.

  • CVE-2023-27896MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

  • CVE-2019-0348MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.

  • CVE-2019-0346MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.

  • CVE-2019-0333MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting…

Page 1 of 3