CVE-2019-0259
- EPSS 0.69%
- Veröffentlicht 15.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:35
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.
CVE-2019-0251
- EPSS 0.31%
- Veröffentlicht 15.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:35
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2408
- EPSS 0.21%
- Veröffentlicht 10.04.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:03:45
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.
CVE-2017-16683
- EPSS 0.55%
- Veröffentlicht 12.12.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.
- EPSS 1.88%
- Veröffentlicht 15.10.2015 20:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.
- EPSS 5.79%
- Veröffentlicht 17.12.2014 19:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
CVE-2014-8311
- EPSS 0.42%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.
CVE-2014-8310
- EPSS 2.51%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.
- EPSS 0.49%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames v...
CVE-2014-8308
- EPSS 0.47%
- Veröffentlicht 16.10.2014 19:55:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.