Sap Businessobjects Business Intelligence vulnerabilities
45 known vulnerabilities affecting sap/businessobjects_business_intelligence.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH12MEDIUM29
Vulnerabilities
Page 2 of 3
CVE-2018-2473P4MEDIUMCVSS 6.5v4.1v4.22018-11-13
CVE-2018-2473 [MEDIUM] CVE-2018-2473: SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Inte
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2019-0346P4MEDIUMCVSS 6.5v4.22019-08-14
CVE-2019-0346 [MEDIUM] CWE-319 CVE-2019-0346: Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Mana
Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems, resulting in Information Disclosure.
nvd
CVE-2023-27894P4MEDIUMCVSS 5.3v420v4302023-03-14
CVE-2023-27894 [MEDIUM] CWE-200 CVE-2023-27894: SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an att
SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further
nvd
CVE-2022-39800P4MEDIUMCVSS 6.1v420v4302022-10-11
CVE-2022-39800 [MEDIUM] CWE-79 CVE-2022-39800: SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by a
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the applica
nvd
CVE-2021-33697P4MEDIUMCVSS 6.1v420v4302021-09-15
CVE-2021-33697 [MEDIUM] CWE-1022 CVE-2021-33697: Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 42
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
nvd
CVE-2023-31406P4MEDIUMCVSS 6.1v420v4302023-05-09
CVE-2023-31406 [MEDIUM] CWE-79 CVE-2023-31406: Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
nvd
CVE-2023-30741P4MEDIUMCVSS 6.1v420v4302023-05-09
CVE-2023-30741 [MEDIUM] CWE-79 CVE-2023-30741: Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
nvd
CVE-2019-0335P4MEDIUMCVSS 6.1v4.1v4.2+1 more2019-08-14
CVE-2019-0335 [MEDIUM] CWE-79 CVE-2019-0335: Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Cons
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user account. The payload is triggered when the mouse cursor is moved over the description field in the list, when generating the little yello
nvd
CVE-2022-41206P4MEDIUMCVSS 5.4v420v4302022-10-11
CVE-2022-41206 [MEDIUM] CWE-79 CVE-2022-41206: SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows a
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.
nvd
CVE-2023-37489P4MEDIUMCVSS 5.3v4302023-09-12
CVE-2023-37489 [MEDIUM] CWE-209 CVE-2023-37489: Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Managemen
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity.
nvd
CVE-2023-31404P4MEDIUMCVSS 5.0v420v4302023-05-09
CVE-2023-31404 [MEDIUM] CWE-200 CVE-2023-31404: Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Ser
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise b
nvd
CVE-2019-0326P4MEDIUMCVSS 6.1v4.1v4.2+1 more2019-07-10
CVE-2019-0326 [MEDIUM] CWE-79 CVE-2019-0326: SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4
SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2018-2431P4MEDIUMCVSS 6.1v4.10v4.202018-07-10
CVE-2018-2431 [MEDIUM] CWE-79 CVE-2018-2431: SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encod
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2019-0331P4MEDIUMCVSS 5.3v4.1v4.2+1 more2019-08-14
CVE-2019-0331 [MEDIUM] CVE-2019-0331: Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), version
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sensitive data such as directory structure, leading to Information Disclosure.
nvd
CVE-2021-33696P4MEDIUMCVSS 5.4v420v4302021-09-15
CVE-2021-33696 [MEDIUM] CWE-79 CVE-2021-33696: SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not s
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.
nvd
CVE-2021-21444P4MEDIUMCVSS 6.1v410v420+1 more2021-02-09
CVE-2021-21444 [MEDIUM] CWE-1021 CVE-2021-21444: SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.
nvd
CVE-2019-0269P4MEDIUMCVSS 5.4v4.10v4.202019-03-12
CVE-2019-0269 [MEDIUM] CWE-79 CVE-2019-0269: SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not
SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2021-21447P4MEDIUMCVSS 5.4v410v4202021-01-12
CVE-2021-21447 [MEDIUM] CWE-79 CVE-2021-21447: SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attac
SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which leads to Stored Cross-Site Scripting.
nvd
CVE-2019-0332P4MEDIUMCVSS 6.1v4.1v4.2+1 more2019-08-14
CVE-2019-0332 [MEDIUM] CWE-79 CVE-2019-0332: SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an at
SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the search and it will be executed while search performs its action, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2018-2432P4MEDIUMCVSS 5.4v4.1v4.2+1 more2018-07-10
CVE-2018-2432 [MEDIUM] CWE-79 CVE-2018-2432: SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.1
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
nvd