VYPR

Businessobjects Business Intelligence Platform

by SAP

CVEs (96)

  • CVE-2026-66763HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored…

  • CVE-2026-0490HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high impact on the availability…

  • CVE-2026-0485HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service…

  • CVE-2023-42478HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.

  • CVE-2022-39013HigOct 11, 2022
    risk 0.49cvss 7.6epss 0.01

    Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability…

  • CVE-2022-27667HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2021-40500HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation…

  • CVE-2020-6247HigMay 12, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system…

  • CVE-2020-6237HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2020-6227HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files.

  • CVE-2019-0352HigSep 10, 2019
    risk 0.49cvss 7.5epss 0.01

    In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.

  • CVE-2018-2471HigOct 9, 2018
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.

  • CVE-2026-0508HigFeb 10, 2026
    risk 0.47cvss 7.3epss 0.00

    The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the…

  • CVE-2019-0396HigNov 13, 2019
    risk 0.46cvss 7.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will…

  • CVE-2020-6245MedMay 12, 2020
    risk 0.44cvss 6.7epss 0.00

    SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

  • CVE-2025-31332MedApr 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability.…

  • CVE-2026-58248MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these…

  • CVE-2026-24324MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable…

  • CVE-2025-0060MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as…

  • CVE-2023-27271MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.

Page 2 of 5