VYPR

Businessobjects Business Intelligence

by SAP

CVEs (51)

  • CVE-2018-2473MedNov 13, 2018
    risk 0.42cvss 6.5epss 0.02

    SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2018-2447MedAug 14, 2018
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.

  • CVE-2023-30740MedMay 9, 2023
    risk 0.41cvss 6.3epss 0.00

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and…

  • CVE-2023-31406MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2023-30741MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2022-39800MedOct 11, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information…

  • CVE-2021-33697MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2021-21444MedFeb 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking…

  • CVE-2019-0335MedAug 14, 2019
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user account. The payload is triggered when the mouse cursor is…

  • CVE-2019-0332MedAug 14, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0326MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2018-2431MedJul 10, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2023-36917MedJul 11, 2023
    risk 0.38cvss 5.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although…

  • CVE-2022-41206MedOct 11, 2022
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be…

  • CVE-2022-22546MedFeb 9, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad) - version 420.

  • CVE-2021-33696MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from…

  • CVE-2021-21447MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which…

  • CVE-2019-0334MedAug 14, 2019
    risk 0.35cvss 5.4epss 0.01

    When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker…

  • CVE-2019-0331MedAug 14, 2019
    risk 0.35cvss 5.3epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sensitive data such as directory structure, leading to Information Disclosure.

  • CVE-2019-0269MedMar 12, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.