CVE-2020-6308
- EPSS 82.06%
- Veröffentlicht 20.10.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:28
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible e...
CVE-2020-6312
- EPSS 0.34%
- Veröffentlicht 09.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:29
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particu...
CVE-2020-6288
- EPSS 0.22%
- Veröffentlicht 09.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:26
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of fil...
CVE-2020-6294
- EPSS 0.31%
- Veröffentlicht 12.08.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:27
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
CVE-2020-6300
- EPSS 0.24%
- Veröffentlicht 12.08.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:27
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not suf...
CVE-2020-6281
- EPSS 0.17%
- Veröffentlicht 14.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
CVE-2020-6278
- EPSS 0.14%
- Veröffentlicht 14.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading ...
CVE-2020-6276
- EPSS 0.17%
- Veröffentlicht 14.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
CVE-2020-6269
- EPSS 0.22%
- Veröffentlicht 10.06.2020 13:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:24
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6245
- EPSS 0.05%
- Veröffentlicht 12.05.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:22
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.