Skip to main content

Vendor/product archive

sap / businessobjects_business_intelligence CVEs

Beta · best-effort

45 CVEs tagged to sap / businessobjects_business_intelligence4 Critical, 10 High, 31 Medium, 0 Low, 0 Unrated.

CVE-2025-23192

Published Jun 10, 2025

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the wo…

CVSS 8.2 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-37179

Published Oct 8, 2024

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file f…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40622

Published Sep 12, 2023

SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive informati…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37489

Published Sep 12, 2023

Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snipp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39440

Published Aug 8, 2023

In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly,…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37490

Published Aug 8, 2023

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36917

Published Jul 11, 2023

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old passw…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31406

Published May 9, 2023

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31404

Published May 9, 2023

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30741

Published May 9, 2023

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30740

Published May 9, 2023

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successf…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28762

Published May 9, 2023

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI u…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28765

Published Apr 11, 2023

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decr…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-27896

Published Mar 14, 2023

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27894

Published Mar 14, 2023

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41203

Published Nov 8, 2022

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-41206

Published Oct 11, 2022

SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39800

Published Oct 11, 2022

SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs whil…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35296

Published Oct 11, 2022

Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32244

Published Sep 13, 2022

Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-32245

Published Aug 10, 2022

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the ne…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-33696

Published Sep 15, 2021

SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2