VYPR

Businessobjects

by SAP

CVEs (29)

  • CVE-2023-0022CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…

  • CVE-2014-9320CriAug 9, 2021
    risk 0.64cvss 9.8epss 0.04

    SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.

  • CVE-2019-0259CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • CVE-2022-35228HigJul 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social…

  • CVE-2022-28214HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and…

  • CVE-2019-0287HigMay 14, 2019
    risk 0.50cvss 7.6epss 0.02

    Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • CVE-2018-2408HigApr 10, 2018
    risk 0.48cvss 7.3epss 0.02

    Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

  • CVE-2019-0289HigMay 14, 2019
    risk 0.46cvss 7.1epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • CVE-2017-16683MedDec 12, 2017
    risk 0.42cvss 6.5epss 0.01

    Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

  • CVE-2023-40623MedSep 12, 2023
    risk 0.40cvss 6.2epss 0.00

    SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system…

  • CVE-2019-0303MedJun 14, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute…

  • CVE-2019-0251MedFeb 15, 2019
    risk 0.40cvss 6.1epss 0.01

    The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-31598MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on…

  • CVE-2026-44743LowJun 9, 2026
    risk 0.24cvss 3.7epss 0.00

    Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application.

  • CVE-2023-28764LowMay 9, 2023
    risk 0.24cvss 3.7epss 0.01

    SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and…

  • CVE-2010-0219Oct 18, 2010
    risk 0.10cvss epss 0.90

    Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web…

  • CVE-2007-6254Mar 20, 2008
    risk 0.01cvss epss 0.06

    Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before CHF74 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2015-7730Oct 15, 2015
    risk 0.00cvss epss 0.04

    SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.

  • CVE-2014-9387Dec 17, 2014
    risk 0.00cvss epss 0.05

    SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.

  • CVE-2014-8311Oct 16, 2014
    risk 0.00cvss epss 0.02

    SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.

Page 1 of 2