SAP

Businessobjects

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 09.05.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 07:55:57

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information su...

  • EPSS 0.17%
  • Veröffentlicht 11.05.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:56:57

During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidential...

  • EPSS 0.8%
  • Veröffentlicht 14.06.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:39

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. This could be used by an attacker to buil...

  • EPSS 1.08%
  • Veröffentlicht 14.05.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:38

Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • EPSS 1.69%
  • Veröffentlicht 14.05.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:38

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • EPSS 2.02%
  • Veröffentlicht 15.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 04:16:35

SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • EPSS 1.14%
  • Veröffentlicht 15.02.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:35

The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • EPSS 1.56%
  • Veröffentlicht 10.04.2018 15:29:01
  • Zuletzt bearbeitet 21.11.2024 04:03:45

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.

  • EPSS 1.41%
  • Veröffentlicht 12.12.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

  • EPSS 3.63%
  • Veröffentlicht 15.10.2015 20:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.