CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML e...Show more |
2Bmc Yellowfinbi2Remedy Smart Reporting Yellowfin BiJun 17, 2026 Jul 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browse...Show more |