VYPR

Businessobjects Bi Platform

by SAP

CVEs (6)

  • CVE-2026-0490HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability…

  • CVE-2026-0485HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service…

  • CVE-2018-2479MedNov 13, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2018-2472MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0262MedFeb 15, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2018-2467MedOct 9, 2018
    risk 0.35cvss 5.3epss 0.01

    In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser such as Chrome the system returns an error with the path of the used application server.