VYPR

Businessobjects Business Intelligence Platform

by SAP

CVEs (96)

  • CVE-2022-39015MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.

  • CVE-2022-29619MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.

  • CVE-2022-27671MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.

  • CVE-2022-22541MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have…

  • CVE-2022-24398MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access information which would otherwise be restricted.

  • CVE-2020-6269MedJun 10, 2020
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2020-6251MedMay 12, 2020
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.

  • CVE-2022-28216MedApr 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access…

  • CVE-2020-6281MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.

  • CVE-2020-6276MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • CVE-2020-6211MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.

  • CVE-2020-6223MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application,…

  • CVE-2020-6216MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-31596MedDec 12, 2022
    risk 0.39cvss 6.0epss 0.01

    Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal)…

  • CVE-2022-35169MedJul 12, 2022
    risk 0.39cvss 6.0epss 0.01

    SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system…

  • CVE-2020-6308MedOct 20, 2020
    risk 0.39cvss 5.3epss 0.62

    SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful…

  • CVE-2024-45281MedSep 10, 2024
    risk 0.38cvss 5.8epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL…

  • CVE-2026-0502MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no…

  • CVE-2025-25245MedMar 11, 2025
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation,…

  • CVE-2022-31598MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on…