VYPR

Sap Businessobjects Business Intelligence Platform (central Management Console)

by SAP

CVEs (6)

  • CVE-2023-0018CriJan 10, 2023
    risk 0.65cvss 10.0epss 0.01

    Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these…

  • CVE-2025-0064HigFeb 11, 2025
    risk 0.57cvss 8.7epss 0.00

    Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high…

  • CVE-2022-27667HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2018-2432MedJul 10, 2018
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced…

  • CVE-2022-39014MedSep 13, 2022
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.

  • CVE-2026-24325MedFeb 10, 2026
    risk 0.31cvss 4.8epss 0.00

    SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the…