CVE-2024-28165
- EPSS 0.49%
- Veröffentlicht 14.05.2024 16:16:43
- Zuletzt bearbeitet 23.10.2025 12:20:36
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
CVE-2023-42472
- EPSS 0.22%
- Veröffentlicht 12.09.2023 02:15:13
- Zuletzt bearbeitet 21.11.2024 08:22:37
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading t...
CVE-2023-27271
- EPSS 0.18%
- Veröffentlicht 14.03.2023 06:15:11
- Zuletzt bearbeitet 21.11.2024 07:52:34
In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.
CVE-2023-24530
- EPSS 0.33%
- Veröffentlicht 14.02.2023 04:15:13
- Zuletzt bearbeitet 21.11.2024 07:48:04
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform opera...
CVE-2023-0020
- EPSS 0.2%
- Veröffentlicht 14.02.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:24
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and li...
CVE-2023-0022
- EPSS 0.4%
- Veröffentlicht 10.01.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:24
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations tha...
CVE-2023-0018
- EPSS 0.64%
- Veröffentlicht 10.01.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:24
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a mal...
CVE-2022-39014
- EPSS 0.25%
- Veröffentlicht 13.09.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:22
Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
CVE-2022-35228
- EPSS 0.18%
- Veröffentlicht 12.07.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:10:56
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, li...
CVE-2022-35169
- EPSS 0.43%
- Veröffentlicht 12.07.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:10:51
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the ...