VYPR

BusinessObjects Business Intelligence Platform (Web Intelligence)

by SAP

CVEs (103)

  • CVE-2020-6269MedJun 10, 2020
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2020-6251MedMay 12, 2020
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.

  • CVE-2019-0348MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted.

  • CVE-2019-0333MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the attacker can then query and receive the whole data set instead of just what is part of their authorized security profile, resulting…

  • CVE-2018-2473MedNov 13, 2018
    risk 0.42cvss 6.5epss 0.02

    SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2023-30740MedMay 9, 2023
    risk 0.41cvss 6.3epss 0.00

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and…

  • CVE-2023-31406MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2023-30741MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2022-28216MedApr 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access…

  • CVE-2021-33697MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2020-6281MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.

  • CVE-2020-6276MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • CVE-2019-0335MedAug 14, 2019
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user account. The payload is triggered when the mouse cursor is…

  • CVE-2019-0332MedAug 14, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0326MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2019-0303MedJun 14, 2019
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to build a special url that execute…

  • CVE-2018-2479MedNov 13, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2018-2472MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-31596MedDec 12, 2022
    risk 0.39cvss 6.0epss 0.01

    Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal)…

  • CVE-2022-35169MedJul 12, 2022
    risk 0.39cvss 6.0epss 0.01

    SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system…

Page 3 of 6