SAP

Businessobjects

38 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 14.05.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:38

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • EPSS 0.73%
  • Veröffentlicht 15.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 04:16:35

SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • EPSS 0.33%
  • Veröffentlicht 15.02.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:35

The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • EPSS 0.21%
  • Veröffentlicht 10.04.2018 15:29:01
  • Zuletzt bearbeitet 21.11.2024 04:03:45

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

  • EPSS 0.55%
  • Veröffentlicht 12.12.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

  • EPSS 1.88%
  • Veröffentlicht 15.10.2015 20:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.

  • EPSS 5.79%
  • Veröffentlicht 17.12.2014 19:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.

  • EPSS 0.42%
  • Veröffentlicht 16.10.2014 19:55:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.

  • EPSS 0.47%
  • Veröffentlicht 16.10.2014 19:55:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.49%
  • Veröffentlicht 16.10.2014 19:55:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames v...