CVE-2025-42985
- EPSS 0.04%
- Veröffentlicht 08.07.2025 00:38:25
- Zuletzt bearbeitet 08.07.2025 16:18:14
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client dat...
CVE-2025-42965
- EPSS 0.04%
- Veröffentlicht 08.07.2025 00:36:02
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer...
CVE-2025-31326
- EPSS 0.04%
- Veröffentlicht 08.07.2025 00:34:21
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or man...
CVE-2025-42988
- EPSS 0.06%
- Veröffentlicht 10.06.2025 00:12:00
- Zuletzt bearbeitet 12.06.2025 16:06:39
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further ena...
CVE-2025-43000
- EPSS 0.02%
- Veröffentlicht 13.05.2025 00:17:59
- Zuletzt bearbeitet 13.05.2025 19:35:25
Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.
CVE-2025-31332
- EPSS 0.01%
- Veröffentlicht 08.04.2025 07:15:36
- Zuletzt bearbeitet 08.04.2025 18:13:53
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on in...
CVE-2025-25245
- EPSS 0.04%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user....
CVE-2025-23185
- EPSS 0.05%
- Veröffentlicht 11.03.2025 01:15:34
- Zuletzt bearbeitet 11.03.2025 01:15:34
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has ac...
CVE-2025-0062
- EPSS 0.05%
- Veröffentlicht 11.03.2025 01:15:33
- Zuletzt bearbeitet 11.03.2025 01:15:33
SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful expl...
CVE-2025-24867
- EPSS 0.15%
- Veröffentlicht 11.02.2025 01:15:10
- Zuletzt bearbeitet 11.02.2025 01:15:10
SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unp...