VYPR

Businessobjects Explorer

by SAP

CVEs (2)

  • CVE-2014-8316Oct 16, 2014
    risk 0.00cvss epss 0.01

    XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrary files via the xmlParameter parameter in an explorationSpaceUpdate request.

  • CVE-2014-8315Oct 16, 2014
    risk 0.00cvss epss 0.01

    polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter.