VYPR

BusinessObjects Business Intelligence Platform (Web Intelligence)

by SAP

CVEs (103)

  • CVE-2020-6308MedOct 20, 2020
    risk 0.39cvss 5.3epss 0.62

    SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful…

  • CVE-2024-45281MedSep 10, 2024
    risk 0.38cvss 5.8epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL…

  • CVE-2023-36917MedJul 11, 2023
    risk 0.38cvss 5.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although…

  • CVE-2025-42896MedDec 9, 2025
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to…

  • CVE-2025-25245MedMar 11, 2025
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation,…

  • CVE-2022-41206MedOct 11, 2022
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be…

  • CVE-2021-42061MedDec 14, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will…

  • CVE-2021-33696MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from…

  • CVE-2021-21447MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which…

  • CVE-2020-6312MedSep 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to…

  • CVE-2020-6288MedSep 9, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type…

  • CVE-2020-6278MedJul 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting

  • CVE-2020-6257MedMay 12, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • CVE-2019-0395MedDec 11, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.

  • CVE-2019-0382MedNov 13, 2019
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.

  • CVE-2019-0378MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image resulting in Stored Cross-Site…

  • CVE-2019-0377MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.

  • CVE-2019-0376MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in the publication name, which can be executed later by the…

  • CVE-2019-0375MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site…

  • CVE-2019-0374MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site Scripting

Page 4 of 6