cbcvebase.

Sap Businessobjects Business Intelligence Platform vulnerabilities

77 known vulnerabilities affecting sap/businessobjects_business_intelligence_platform.

Total CVEs
77
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH22MEDIUM47

Vulnerabilities

Page 2 of 4
CVE-2022-27667P3HIGHCVSS 7.5v4302022-04-12
CVE-2022-27667 [HIGH] CWE-200 CVE-2022-27667: Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Cons Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2018-2471P3HIGHCVSS 7.5v4.10v4.202018-10-09
CVE-2018-2471 [HIGH] CVE-2018-2471: Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2023-27271P3HIGHCVSS 7.5v420v4302023-03-14
CVE-2023-27271 [HIGH] CWE-918 CVE-2023-27271: In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacke In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.
nvd
CVE-2020-6237P3HIGHCVSS 7.5v4.1v4.22020-04-14
CVE-2020-6237 [HIGH] CVE-2020-6237: Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dsw Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2020-6227P3HIGHCVSS 7.5v4.22020-04-14
CVE-2020-6227 [HIGH] CWE-20 CVE-2020-6227: SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows att SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files.
nvd
CVE-2023-27896P3HIGHCVSS 7.5v420v4302023-03-14
CVE-2023-27896 [HIGH] CWE-918 CVE-2023-27896: In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.
nvd
CVE-2019-0398P3HIGHCVSS 8.8v4.1v4.2+1 more2019-12-11
CVE-2019-0398 [HIGH] CWE-352 CVE-2019-0398: Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
nvd
CVE-2026-24324P3MEDIUMCVSS 6.5v430v2025+1 more2026-02-10
CVE-2026-24324 [MEDIUM] CWE-405 CVE-2026-24324: SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker wit SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (C
nvd
CVE-2019-0352P3HIGHCVSS 7.5v4.10v4.20+1 more2019-09-10
CVE-2019-0352 [HIGH] CWE-200 CVE-2019-0352: In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynam In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.
nvd
CVE-2023-0020P3HIGHCVSS 7.1v420v4302023-02-14
CVE-2023-0020 [HIGH] CWE-200 CVE-2023-0020: SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated atta SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.
nvd
CVE-2025-0060P3MEDIUMCVSS 6.5v420v430+1 more2025-01-14
CVE-2025-0060 [MEDIUM] CWE-94 CVE-2025-0060: SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted acce SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity
nvd
CVE-2025-0064P3MEDIUMCVSS 6.5v430v20252025-02-11
CVE-2025-0064 [MEDIUM] CWE-732 CVE-2025-0064: Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intell Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.
nvd
CVE-2019-0396P4HIGHCVSS 7.1v4.0v4.12019-11-13
CVE-2019-0396 [HIGH] CWE-20 CVE-2019-0396: SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in v SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific
nvd
CVE-2022-22541P3MEDIUMCVSS 6.5v420v4302022-04-12
CVE-2022-22541 [MEDIUM] CWE-213 CVE-2022-22541: SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users t SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.
nvd
CVE-2022-29619P4MEDIUMCVSS 6.5v420v4302022-07-12
CVE-2022-29619 [MEDIUM] CWE-863 CVE-2022-29619: Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 a Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.
nvd
CVE-2020-6269P4MEDIUMCVSS 6.5v4.22020-06-10
CVE-2020-6269 [MEDIUM] CVE-2020-6269: Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2020-6251P4MEDIUMCVSS 6.5v4.22020-05-12
CVE-2020-6251 [MEDIUM] CVE-2020-6251: Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, ver Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2022-35169P4MEDIUMCVSS 6.0v420v4302022-07-12
CVE-2022-35169 [MEDIUM] CWE-200 CVE-2022-35169: SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker wit SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availabil
nvd
CVE-2023-27894P4MEDIUMCVSS 5.3v420v4302023-03-14
CVE-2023-27894 [MEDIUM] CWE-200 CVE-2023-27894: SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an att SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further
nvd
CVE-2025-31332P4HIGHCVSS 7.1v4302025-04-08
CVE-2025-31332 [HIGH] CWE-277 CVE-2025-31332: Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerability does not disclose any sensitive data.
nvd
Sap Businessobjects Business Intelligence Platform vulnerabilities | cvebase