CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Apr 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a...Show more |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Dec 12, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable pag...Show more |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Oct 10, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve th...Show more |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Feb 9, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad) - version 420. |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Jul 14, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend...Show more |