VYPR

Businessobjects Business Intelligence

by SAP

CVEs (51)

  • CVE-2018-2432MedJul 10, 2018
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced…

  • CVE-2023-37489MedSep 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's…

  • CVE-2022-32244MedSep 13, 2022
    risk 0.34cvss 5.2epss 0.00

    Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same…

  • CVE-2023-31404MedMay 9, 2023
    risk 0.33cvss 5.0epss 0.00

    Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of…

  • CVE-2023-27894MedMar 14, 2023
    risk 0.33cvss 5.0epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker…

  • CVE-2022-35296MedOct 11, 2022
    risk 0.32cvss 4.9epss 0.01

    Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading…

  • CVE-2023-39440MedAug 8, 2023
    risk 0.29cvss 4.4epss 0.00

    In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the…

  • CVE-2023-23856MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.00

    In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable…

  • CVE-2021-33667MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.

  • CVE-2018-2483MedNov 13, 2018
    risk 0.28cvss 4.3epss 0.01

    HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.

  • CVE-2026-27683MedApr 14, 2026
    risk 0.27cvss 4.1epss 0.00

    SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This…

Page 3 of 3