SAP

Businessobjects

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 12.05.2026 02:19:08
  • Zuletzt bearbeitet 12.05.2026 14:19:41

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the a...

  • EPSS 0.03%
  • Veröffentlicht 14.04.2026 00:08:15
  • Zuletzt bearbeitet 17.04.2026 15:18:16

SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restr...

  • EPSS 0.07%
  • Veröffentlicht 14.04.2026 00:06:18
  • Zuletzt bearbeitet 17.04.2026 15:18:16

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the applica...

  • EPSS 0.01%
  • Veröffentlicht 10.02.2026 03:04:30
  • Zuletzt bearbeitet 17.02.2026 15:14:43

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets exec...

  • EPSS 0.02%
  • Veröffentlicht 10.02.2026 03:04:21
  • Zuletzt bearbeitet 17.02.2026 15:15:09

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially...

  • EPSS 0.01%
  • Veröffentlicht 10.02.2026 03:01:41
  • Zuletzt bearbeitet 17.02.2026 16:06:15

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unv...

  • EPSS 0.12%
  • Veröffentlicht 10.02.2026 03:01:20
  • Zuletzt bearbeitet 17.02.2026 16:06:59

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authentication, which prevents the legitimate users from accessing the platform. As a result, it has a high...

  • EPSS 0.06%
  • Veröffentlicht 10.02.2026 03:00:49
  • Zuletzt bearbeitet 17.02.2026 16:11:42

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could...

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 09.12.2025 02:15:28
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resultin...

  • EPSS 0.16%
  • Veröffentlicht 08.07.2025 00:38:25
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client dat...