CVE-2024-25646
- EPSS 0.1%
- Veröffentlicht 09.04.2024 01:15:48
- Zuletzt bearbeitet 29.10.2025 14:08:12
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confide...
CVE-2023-40623
- EPSS 0.15%
- Veröffentlicht 12.09.2023 03:15:13
- Zuletzt bearbeitet 21.11.2024 08:19:50
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete a...
CVE-2023-28764
- EPSS 0.38%
- Veröffentlicht 09.05.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 07:55:57
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information su...
CVE-2022-28214
- EPSS 0.03%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:56:57
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidential...
CVE-2019-0303
- EPSS 0.23%
- Veröffentlicht 14.06.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:39
SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to buil...
CVE-2019-0289
- EPSS 0.29%
- Veröffentlicht 14.05.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:38
Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.
CVE-2019-0287
- EPSS 0.49%
- Veröffentlicht 14.05.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:38
Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.
CVE-2019-0259
- EPSS 0.69%
- Veröffentlicht 15.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:35
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.
CVE-2019-0251
- EPSS 0.31%
- Veröffentlicht 15.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:35
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2408
- EPSS 0.21%
- Veröffentlicht 10.04.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:03:45
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.