cbcvebase.

Sap Se Sap Businessobjects Business Intelligence Platform vulnerabilities

82 known vulnerabilities affecting sap_se/sap_businessobjects_business_intelligence_platform.

Total CVEs
82
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH19MEDIUM59

Vulnerabilities

Page 1 of 5
CVE-2020-6308P1MEDIUMCVSS 5.3ExploitedPoCfixed in 410fixed in 420+1 more2020-10-20
CVE-2020-6308 [MEDIUM] CWE-918 CVE-2020-6308: SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows a SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrast
nvd
CVE-2024-41730P2CRITICALCVSS 9.8vENTERPRISE 430v4402024-08-13
CVE-2024-41730 [CRITICAL] CWE-862 CVE-2024-41730: In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality, integrity and availability.
nvd
CVE-2022-28213P2HIGHCVSS 8.1PoCv420v4302022-04-12
CVE-2022-28213 [HIGH] CWE-112 CVE-2022-28213: When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
nvd
CVE-2023-40622P3CRITICALCVSS 9.9v420v4302023-09-12
CVE-2023-40622 [CRITICAL] CWE-732 CVE-2023-40622: SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, an
nvd
CVE-2022-41203P3HIGHCVSS 8.8v= 4.2v= 4.32022-11-08
CVE-2022-41203 [HIGH] CWE-502 CVE-2022-41203: In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), a In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted data vulnerability. This could highly compromise the Co
nvd
CVE-2025-0061P3CRITICALCVSS 9.1vENTERPRISE 420v430+1 more2025-01-14
CVE-2025-0061 [CRITICAL] CWE-497 CVE-2025-0061: SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform ses SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.
nvd
CVE-2021-40500P3HIGHCVSS 7.5fixed in 420fixed in 4302021-10-12
CVE-2021-40500 [HIGH] CWE-611 CVE-2021-40500: SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.
nvd
CVE-2022-35228P3HIGHCVSS 8.8v420v4302022-07-12
CVE-2022-35228 [HIGH] CWE-352 CVE-2022-35228: SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the ne SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise t
nvd
CVE-2022-39013P3HIGHCVSS 7.6v420v4302022-10-11
CVE-2022-39013 [HIGH] CWE-200 CVE-2022-39013: Under certain conditions an authenticated attacker can get access to OS credentials. Getting access Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.
nvd
CVE-2019-0268P3HIGHCVSS 8.1fixed in 4.1fixed in 4.2+1 more2019-03-12
CVE-2019-0268 [HIGH] CWE-91 CVE-2019-0268: SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
nvd
CVE-2022-32245P3HIGHCVSS 8.2v420v4302022-08-10
CVE-2022-32245 [HIGH] CWE-319 CVE-2022-32245: SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an un SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compr
nvd
CVE-2023-36917P3HIGHCVSS 7.5v4.20v4302023-07-11
CVE-2023-36917 [HIGH] CWE-307 CVE-2023-36917: SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attack SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could
nvd
CVE-2024-28165P3CRITICALCVSS 9.3v430v4402024-05-14
CVE-2024-28165 [CRITICAL] CWE-79 CVE-2024-28165: SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacke SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
nvd
CVE-2023-30740P3HIGHCVSS 7.6v420v4302023-05-09
CVE-2023-30740 [HIGH] CWE-200 CVE-2023-30740: SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated atta SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and availability of the application.
nvd
CVE-2023-42472P3HIGHCVSS 7.3v4202023-09-12
CVE-2023-42472 [HIGH] CWE-434 CVE-2023-42472: Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web In Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request, modify the content type and the e
nvd
CVE-2026-0508P3HIGHCVSS 8.1vENTERPRISE 430v2025+1 more2026-02-10
CVE-2026-0508 [HIGH] CWE-601 CVE-2026-0508: The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high pr The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently download the malicious content. This
nvd
CVE-2022-27667P3HIGHCVSS 7.5v4302022-04-12
CVE-2022-27667 [HIGH] CWE-200 CVE-2022-27667: Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Cons Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2019-0287P3HIGHCVSS 7.6fixed in 4.2fixed in 4.32019-05-14
CVE-2019-0287 [HIGH] CVE-2019-0287: Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Serv Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2019-0398P3HIGHCVSS 8.8vbefore 4.1vbefore 4.2+1 more2019-12-11
CVE-2019-0398 [HIGH] CWE-352 CVE-2019-0398: Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
nvd
CVE-2026-24324P3MEDIUMCVSS 6.5vENTERPRISE 430v2025+1 more2026-02-10
CVE-2026-24324 [MEDIUM] CWE-405 CVE-2026-24324: SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker wit SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (C
nvd
Sap Se Sap Businessobjects Business Intelligence Platform vulnerabilities | cvebase