CVE-2021-42061
- EPSS 0.3%
- Veröffentlicht 14.12.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:27:10
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some da...
CVE-2021-40500
- EPSS 1.21%
- Veröffentlicht 12.10.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:24:16
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network...
CVE-2021-33679
- EPSS 0.16%
- Veröffentlicht 14.09.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 06:09:20
The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored maliciou...
CVE-2020-26831
- EPSS 0.62%
- Veröffentlicht 09.12.2020 17:15:31
- Zuletzt bearbeitet 21.11.2024 05:20:21
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitra...
CVE-2020-6308
- EPSS 82.06%
- Veröffentlicht 20.10.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:28
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible e...
CVE-2020-6288
- EPSS 0.22%
- Veröffentlicht 09.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:26
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of fil...
CVE-2020-6312
- EPSS 0.34%
- Veröffentlicht 09.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:29
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particu...
CVE-2020-6300
- EPSS 0.24%
- Veröffentlicht 12.08.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:27
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not suf...
CVE-2020-6294
- EPSS 0.31%
- Veröffentlicht 12.08.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:27
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
CVE-2020-6281
- EPSS 0.17%
- Veröffentlicht 14.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.