CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Oct 23, 2025 Jun 10, 2025 N/A· v4 7.6 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, the script will execute in their...Show more |
1Sap 1Businessobjects Business Intelligence Nov 14, 2024 Oct 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, caus...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Sep 12, 2023 N/A· v4 9.9 CRITICAL· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On succ...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Sep 12, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low imp...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Aug 8, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to ge...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Aug 8, 2023 N/A· v4 9.0 CRITICAL· v3 N/A· v2 SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful e...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 May 9, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful e...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 May 9, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high im...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 May 9, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user int...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gai...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Mar 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not acc...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Nov 8, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with ano...Show more |
1Sap 1Businessobjects Business Intelligence May 20, 2025 Oct 11, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Mana...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Oct 11, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successf...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Oct 11, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explici...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Sep 13, 2022 N/A· v4 5.2 MEDIUM· v3 N/A· v2 Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs t...Show more |