Sap Businessobjects Business Intelligence vulnerabilities

45 known vulnerabilities affecting sap/businessobjects_business_intelligence.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH12MEDIUM29

Vulnerabilities

Page 3 of 3
CVE-2018-2446HIGHCVSS 7.5v4.1v4.22018-08-14
CVE-2018-2446 [HIGH] CVE-2018-2446: Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticate Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
nvd
CVE-2018-2447MEDIUMCVSS 6.5v4.22018-08-14
CVE-2018-2447 [MEDIUM] CWE-89 CVE-2018-2447: SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attac SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.
nvd
CVE-2018-2427HIGHCVSS 8.8v4.10v4.202018-07-10
CVE-2018-2427 [HIGH] CWE-94 CVE-2018-2427: SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (ve SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
nvd
CVE-2018-2431MEDIUMCVSS 6.1v4.10v4.202018-07-10
CVE-2018-2431 [MEDIUM] CWE-79 CVE-2018-2431: SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encod SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2018-2432MEDIUMCVSS 5.4v4.1v4.2+1 more2018-07-10
CVE-2018-2432 [MEDIUM] CWE-79 CVE-2018-2432: SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.1 SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
nvd
Sap Businessobjects Business Intelligence vulnerabilities | cvebase