CVE-2019-0287
- EPSS 0.5%
- Veröffentlicht 14.05.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:38
Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.
CVE-2019-0259
- EPSS 0.73%
- Veröffentlicht 15.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:35
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.
CVE-2019-0251
- EPSS 0.33%
- Veröffentlicht 15.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:35
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2408
- EPSS 0.21%
- Veröffentlicht 10.04.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:03:45
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.
CVE-2017-16683
- EPSS 0.55%
- Veröffentlicht 12.12.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.
- EPSS 1.88%
- Veröffentlicht 15.10.2015 20:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.
- EPSS 5.79%
- Veröffentlicht 17.12.2014 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
CVE-2014-8311
- EPSS 0.42%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.
CVE-2014-8308
- EPSS 0.47%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.49%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames v...