SAP

Businessobjects

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 11.03.2025 01:15:35
  • Zuletzt bearbeitet 24.10.2025 18:41:16

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user....

  • EPSS 0.28%
  • Veröffentlicht 11.03.2025 01:15:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has ac...

  • EPSS 0.27%
  • Veröffentlicht 11.03.2025 01:15:33
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful expl...

  • EPSS 0.26%
  • Veröffentlicht 11.02.2025 01:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unp...

  • EPSS 0.37%
  • Veröffentlicht 11.02.2025 01:15:09
  • Zuletzt bearbeitet 23.10.2025 18:41:05

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system....

  • EPSS 0.51%
  • Veröffentlicht 14.01.2025 01:15:16
  • Zuletzt bearbeitet 24.10.2025 19:14:21

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the d...

  • EPSS 0.4%
  • Veröffentlicht 14.01.2025 01:15:16
  • Zuletzt bearbeitet 24.10.2025 19:15:58

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this i...

  • EPSS 0.31%
  • Veröffentlicht 10.12.2024 01:15:05
  • Zuletzt bearbeitet 28.10.2025 18:29:49

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the applic...

  • EPSS 0.42%
  • Veröffentlicht 09.04.2024 01:15:48
  • Zuletzt bearbeitet 29.10.2025 14:08:12

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confide...

  • EPSS 0.37%
  • Veröffentlicht 12.09.2023 03:15:13
  • Zuletzt bearbeitet 21.11.2024 08:19:50

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete a...