VYPR

BusinessObjects Business Intelligence Platform (Web Intelligence)

by SAP

CVEs (103)

  • CVE-2019-0268HigMar 12, 2019
    risk 0.53cvss 8.1epss 0.02

    SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2024-37179HigOct 8, 2024
    risk 0.50cvss 7.7epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.

  • CVE-2019-0287HigMay 14, 2019
    risk 0.50cvss 7.6epss 0.02

    Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • CVE-2023-42478HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.

  • CVE-2021-40500HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation…

  • CVE-2020-6247HigMay 12, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system…

  • CVE-2020-6237HigApr 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2018-2471HigOct 9, 2018
    risk 0.49cvss 7.5epss 0.02

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.

  • CVE-2026-0508HigFeb 10, 2026
    risk 0.47cvss 7.3epss 0.00

    The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the…

  • CVE-2019-0396HigNov 13, 2019
    risk 0.46cvss 7.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will…

  • CVE-2019-0289HigMay 14, 2019
    risk 0.46cvss 7.1epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • CVE-2020-6245MedMay 12, 2020
    risk 0.44cvss 6.7epss 0.00

    SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

  • CVE-2025-31332MedApr 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability.…

  • CVE-2026-24324MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable…

  • CVE-2025-0060MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as…

  • CVE-2023-27896MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

  • CVE-2023-27271MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.

  • CVE-2022-29619MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.

  • CVE-2022-22541MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have…

  • CVE-2022-24398MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access information which would otherwise be restricted.

Page 2 of 6