VYPR

BusinessObjects Business Intelligence Platform (Web Intelligence)

by SAP

CVEs (103)

  • CVE-2024-41730CriAug 13, 2024
    risk 0.70cvss 9.8epss 0.76

    In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality,…

  • CVE-2023-28765CriApr 11, 2023
    risk 0.65cvss 9.8epss 0.15

    An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the…

  • CVE-2023-40622CriSep 12, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise…

  • CVE-2023-25616CriMar 14, 2023
    risk 0.64cvss 9.9epss 0.01

    In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack…

  • CVE-2023-0022CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…

  • CVE-2022-41267CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on…

  • CVE-2020-6242CriMay 12, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate,…

  • CVE-2016-6818CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS commands via a crafted SQL…

  • CVE-2018-2445CriAug 14, 2018
    risk 0.62cvss 9.6epss 0.01

    AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2023-28762CriMay 9, 2023
    risk 0.59cvss 9.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the…

  • CVE-2020-6294CriAug 12, 2020
    risk 0.59cvss 9.1epss 0.02

    Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

  • CVE-2025-0064HigFeb 11, 2025
    risk 0.57cvss 8.7epss 0.00

    Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high…

  • CVE-2025-0061HigJan 14, 2025
    risk 0.57cvss 8.7epss 0.01

    SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.

  • CVE-2023-42472HigSep 12, 2023
    risk 0.57cvss 8.7epss 0.01

    Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an…

  • CVE-2022-28213HigApr 12, 2022
    risk 0.57cvss 8.1epss 0.12

    When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful…

  • CVE-2019-0398HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

  • CVE-2023-24530HigFeb 14, 2023
    risk 0.55cvss 8.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely…

  • CVE-2023-0020HigFeb 14, 2023
    risk 0.55cvss 8.5epss 0.01

    SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of…

  • CVE-2024-28165HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.01

    SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application

  • CVE-2022-32245HigAug 10, 2022
    risk 0.53cvss 8.2epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and…

Page 1 of 6