cbcvebase.

Sap Businessobjects Business Intelligence Platform vulnerabilities

77 known vulnerabilities affecting sap/businessobjects_business_intelligence_platform.

Total CVEs
77
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH22MEDIUM47

Vulnerabilities

Page 3 of 4
CVE-2020-6288P4MEDIUMCVSS 5.3v4.1v4.22020-09-09
CVE-2020-6288 [MEDIUM] CWE-434 CVE-2020-6288: SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an atta SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type vulnerability. The attacker can modify some formulas and display erroneous conten
nvd
CVE-2025-42988P4MEDIUMCVSS 5.3v430v2025+1 more2025-06-10
CVE-2025-42988 [MEDIUM] CWE-918 CVE-2025-42988: Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthentica Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable the researcher to cause SSRF. It has no impact on integrity and availability of the application.
nvd
CVE-2024-34684P4MEDIUMCVSS 6.0v420v430+1 more2024-06-11
CVE-2024-34684 [MEDIUM] CWE-200 CVE-2024-34684: On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated att On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.
nvd
CVE-2022-27671P4MEDIUMCVSS 6.5v420v4302022-04-12
CVE-2022-27671 [MEDIUM] CWE-201 CVE-2022-27671: A CSRF token visible in the URL may possibly lead to information disclosure vulnerability. A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
nvd
CVE-2025-25245P4MEDIUMCVSS 6.1v430v20252025-03-11
CVE-2025-25245 [MEDIUM] CWE-79 CVE-2025-25245: SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web appl SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within t
nvd
CVE-2022-39014P4MEDIUMCVSS 5.3v4302022-09-13
CVE-2022-39014 [MEDIUM] CWE-311 CVE-2022-39014: Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Conso Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
nvd
CVE-2020-6245P4MEDIUMCVSS 6.7v4.22020-05-12
CVE-2020-6245 [MEDIUM] CWE-99 CVE-2020-6245: SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
nvd
CVE-2022-28216P4MEDIUMCVSS 6.1v4202022-04-12
CVE-2022-28216 [MEDIUM] CWE-79 CVE-2022-28216: SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access certain reports causing a limited impact on confidentiality of the applicatio
nvd
CVE-2023-0018P4MEDIUMCVSS 6.1v420v4302023-01-10
CVE-2023-0018 [MEDIUM] CWE-79 CVE-2023-0018: Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intellig Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens those reports would be susceptible to
nvd
CVE-2021-33679P4MEDIUMCVSS 5.4v4202021-09-14
CVE-2021-33679 [MEDIUM] CWE-79 CVE-2021-33679: The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the ap The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker to compromise their confidentialit
nvd
CVE-2020-6312P4MEDIUMCVSS 5.4v4.1v4.22020-09-09
CVE-2020-6312 [MEDIUM] CWE-79 CVE-2020-6312: SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses a
nvd
CVE-2024-32732P4MEDIUMCVSS 5.3v430v20252024-12-10
CVE-2024-32732 [MEDIUM] CWE-497 CVE-2024-32732: Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to ac Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.
nvd
CVE-2020-6211P4MEDIUMCVSS 6.1v4.1v4.22020-04-14
CVE-2020-6211 [MEDIUM] CWE-601 CVE-2020-6211: SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attac SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
nvd
CVE-2024-45281P4MEDIUMCVSS 5.8v4302024-09-10
CVE-2024-45281 [MEDIUM] CWE-426 CVE-2024-45281: SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client deskto SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and in
nvd
CVE-2018-2397P4MEDIUMCVSS 5.4v4.00v4.10+2 more2018-03-14
CVE-2018-2397 [MEDIUM] CWE-79 CVE-2018-2397: In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Manageme In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
nvd
CVE-2020-6189P4MEDIUMCVSS 5.3v4.22020-02-12
CVE-2020-6189 [MEDIUM] CWE-209 CVE-2020-6189: Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.
nvd
CVE-2020-6278P4MEDIUMCVSS 5.4v4.1v4.22020-07-14
CVE-2020-6278 [MEDIUM] CWE-79 CVE-2020-6278: SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allow SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting
nvd
CVE-2019-0377P4MEDIUMCVSS 5.4v4.0v4.12019-10-08
CVE-2019-0377 [MEDIUM] CWE-79 CVE-2019-0377: SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.
nvd
CVE-2019-0376P4MEDIUMCVSS 5.4v4.0v4.1+1 more2019-10-08
CVE-2019-0376 [MEDIUM] CWE-79 CVE-2019-0376: SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in the publication name, which can be executed later by the victim, resulting in Stored Cross-Site Scripting.
nvd
CVE-2020-6223P4MEDIUMCVSS 6.1v4.1v4.22020-04-14
CVE-2020-6223 [MEDIUM] CWE-601 CVE-2020-6223: The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoofing.
nvd
Sap Businessobjects Business Intelligence Platform vulnerabilities | cvebase