VYPR
Vendor

Ibi

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2025-11548CriOct 14, 2025
    risk 0.60cvss epss 0.00

    A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

  • CVE-2020-14203HigJun 22, 2020
    risk 0.57cvss 8.8epss 0.00

    WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with…

  • CVE-2020-14204HigJun 22, 2020
    risk 0.53cvss 8.2epss 0.02

    In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTTP requests via a crafted HTTP request to /ibi_apps/WFServlet.cfg because XML external entity injection is possible. This is…

  • CVE-2020-14202MedJun 22, 2020
    risk 0.40cvss 6.1epss 0.01

    WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters.