CVE-2024-45281
- EPSS 0.03%
- Published 10.09.2024 05:15:12
- Last modified 10.09.2024 12:09:50
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnera...
- EPSS 0.08%
- Published 11.06.2024 03:15:10
- Last modified 21.11.2024 09:19:11
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative ...
CVE-2023-42472
- EPSS 0.22%
- Published 12.09.2023 02:15:13
- Last modified 21.11.2024 08:22:37
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading t...
CVE-2023-27271
- EPSS 0.14%
- Published 14.03.2023 06:15:11
- Last modified 21.11.2024 07:52:34
In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.
CVE-2023-24530
- EPSS 0.25%
- Published 14.02.2023 04:15:13
- Last modified 21.11.2024 07:48:04
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform opera...
CVE-2023-0020
- EPSS 0.15%
- Published 14.02.2023 04:15:10
- Last modified 21.11.2024 07:36:24
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and li...
CVE-2023-0022
- EPSS 0.4%
- Published 10.01.2023 04:15:10
- Last modified 21.11.2024 07:36:24
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations tha...
CVE-2023-0018
- EPSS 0.63%
- Published 10.01.2023 04:15:09
- Last modified 21.11.2024 07:36:24
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a mal...
CVE-2022-39014
- EPSS 0.25%
- Published 13.09.2022 16:15:09
- Last modified 21.11.2024 07:17:22
Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
CVE-2022-35228
- EPSS 0.18%
- Published 12.07.2022 21:15:11
- Last modified 21.11.2024 07:10:56
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, li...