VYPR

Businessobjects Financial Consolidation

by SAP

CVEs (3)

  • CVE-2025-30016CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.00

    SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

  • CVE-2017-6061MedMar 16, 2017
    risk 0.31cvss 4.7epss 0.01

    Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.

  • CVE-2026-40136MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data