CVE-2026-66772
- EPSS 0.18%
- Veröffentlicht 11.08.2026 00:18:49
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain li...
CVE-2026-66763
- EPSS 0.13%
- Veröffentlicht 11.08.2026 00:17:50
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects an...
CVE-2026-58248
- EPSS 0.28%
- Veröffentlicht 11.08.2026 00:17:16
- Zuletzt bearbeitet 26.08.2026 19:00:14
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected ...
CVE-2026-44755
- EPSS 0.11%
- Veröffentlicht 09.06.2026 00:21:39
- Zuletzt bearbeitet 23.07.2026 08:10:00
SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has a low impact on integrity and does not af...
CVE-2026-44743
- EPSS 0.19%
- Veröffentlicht 09.06.2026 00:20:26
- Zuletzt bearbeitet 23.07.2026 08:10:00
Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availabi...
CVE-2026-0502
- EPSS 0.12%
- Veröffentlicht 12.05.2026 02:19:08
- Zuletzt bearbeitet 12.05.2026 14:19:41
Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the a...
CVE-2026-27683
- EPSS 0.19%
- Veröffentlicht 14.04.2026 00:08:15
- Zuletzt bearbeitet 17.04.2026 15:18:16
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restr...
CVE-2026-24318
- EPSS 0.17%
- Veröffentlicht 14.04.2026 00:06:18
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the applica...
CVE-2026-24325
- EPSS 0.19%
- Veröffentlicht 10.02.2026 03:04:30
- Zuletzt bearbeitet 17.02.2026 15:14:43
SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets exec...
CVE-2026-24324
- EPSS 0.34%
- Veröffentlicht 10.02.2026 03:04:21
- Zuletzt bearbeitet 17.02.2026 15:15:09
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially...