cbcvebase.

Sap Businessobjects Business Intelligence vulnerabilities

45 known vulnerabilities affecting sap/businessobjects_business_intelligence.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH12MEDIUM29

Vulnerabilities

Page 3 of 3
CVE-2019-0334P4MEDIUMCVSS 5.4v4.1v4.2+1 more2019-08-14
CVE-2019-0334 [MEDIUM] CWE-79 CVE-2019-0334: When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), version When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker could also access other sensitive information, leading to Stored Cross Site Sc
nvd
CVE-2022-35296P4MEDIUMCVSS 4.9v420v4302022-10-11
CVE-2022-35296 [MEDIUM] CWE-200 CVE-2022-35296: Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Versio Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.
nvd
CVE-2022-32244P4MEDIUMCVSS 5.2v420v4302022-09-13
CVE-2022-32244 [MEDIUM] CWE-200 CVE-2022-32244: Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restri
nvd
CVE-2018-2483P4MEDIUMCVSS 4.3v4.1v4.22018-11-13
CVE-2018-2483 [MEDIUM] CWE-287 CVE-2018-2483: HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.
nvd
CVE-2023-39440P4MEDIUMCVSS 4.4v4202023-08-08
CVE-2023-39440 [MEDIUM] CWE-312 CVE-2023-39440: In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular progr In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the attacker needs to have local access to the system. There is no impact on a
nvd
Sap Businessobjects Business Intelligence vulnerabilities | cvebase