Sap Businessobjects Edge vulnerabilities

6 known vulnerabilities affecting sap/businessobjects_edge.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2014-9320CRITICALCVSS 9.8v4.12021-08-09
CVE-2014-9320 [CRITICAL] CWE-287 CVE-2014-9320: SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_T SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
nvd
CVE-2015-2074HIGHCVSS 7.5v4.02021-08-09
CVE-2015-2074 [HIGH] CWE-22 CVE-2015-2074: The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attac The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.
nvd
CVE-2015-2073HIGHCVSS 7.5v4.02021-08-09
CVE-2015-2073 [HIGH] CWE-22 CVE-2015-2073: The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attac The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.
nvd
CVE-2015-7730CRITICALCVSS 10.0v4.02015-10-15
CVE-2015-7730 [CRITICAL] CWE-119 CVE-2015-7730: SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.
nvd
CVE-2015-2075MEDIUMCVSS 5.0v4.02015-02-27
CVE-2015-2075 [MEDIUM] CWE-264 CVE-2015-2075: SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue v SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.
nvd
CVE-2015-2076MEDIUMCVSS 5.0v4.02015-02-27
CVE-2015-2076 [MEDIUM] CWE-200 CVE-2015-2076: The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive inf The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.
nvd