SAP

Businessobjects

38 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 08.07.2025 00:38:25
  • Last modified 08.07.2025 16:18:14

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client dat...

  • EPSS 0.04%
  • Published 08.07.2025 00:36:02
  • Last modified 08.07.2025 16:18:14

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer...

  • EPSS 0.04%
  • Published 08.07.2025 00:34:21
  • Last modified 08.07.2025 16:18:14

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or man...

Media report
  • EPSS 0.06%
  • Published 10.06.2025 00:12:00
  • Last modified 12.06.2025 16:06:39

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further ena...

Media report
  • EPSS 0.02%
  • Published 13.05.2025 00:17:59
  • Last modified 13.05.2025 19:35:25

Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.

  • EPSS 0.01%
  • Published 08.04.2025 07:15:36
  • Last modified 08.04.2025 18:13:53

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on in...

  • EPSS 0.04%
  • Published 11.03.2025 01:15:35
  • Last modified 11.03.2025 01:15:35

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user....

  • EPSS 0.05%
  • Published 11.03.2025 01:15:34
  • Last modified 11.03.2025 01:15:34

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has ac...

  • EPSS 0.05%
  • Published 11.03.2025 01:15:33
  • Last modified 11.03.2025 01:15:33

SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful expl...

  • EPSS 0.15%
  • Published 11.02.2025 01:15:10
  • Last modified 11.02.2025 01:15:10

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unp...