VYPR

Businessobjects Financial Consolidation

by SAP

CVEs (4)

  • CVE-2018-2444MedAug 14, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2017-14516MedDec 3, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.

  • CVE-2017-6061MedMar 16, 2017
    risk 0.31cvss 4.7epss 0.02

    Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor…

  • CVE-2026-40136MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on…