SAP

Businessobjects Business Intelligence Platform

60 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.62%
  • Published 09.12.2020 17:15:31
  • Last modified 21.11.2024 05:20:21

SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitra...

  • EPSS 82.06%
  • Published 20.10.2020 14:15:14
  • Last modified 21.11.2024 05:35:28

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible e...

  • EPSS 0.34%
  • Published 09.09.2020 13:15:11
  • Last modified 21.11.2024 05:35:29

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particu...

  • EPSS 0.22%
  • Published 09.09.2020 13:15:11
  • Last modified 21.11.2024 05:35:26

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of fil...

  • EPSS 0.24%
  • Published 12.08.2020 14:15:14
  • Last modified 21.11.2024 05:35:27

SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not suf...

  • EPSS 0.44%
  • Published 12.08.2020 14:15:14
  • Last modified 21.11.2024 05:35:27

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

  • EPSS 0.17%
  • Published 14.07.2020 13:15:12
  • Last modified 21.11.2024 05:35:25

SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.

  • EPSS 0.14%
  • Published 14.07.2020 13:15:12
  • Last modified 21.11.2024 05:35:25

SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading ...

  • EPSS 0.17%
  • Published 14.07.2020 13:15:12
  • Last modified 21.11.2024 05:35:25

SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • EPSS 0.22%
  • Published 10.06.2020 13:15:18
  • Last modified 21.11.2024 05:35:24

Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.