Vulnerabilities > SAP > Businessobjects Business Intelligence Platform > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-11 CVE-2024-34684 Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 420/430/440
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account.
local
low complexity
sap
6.0
2023-01-10 CVE-2023-0018 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload.
network
low complexity
sap CWE-79
6.1
2022-09-13 CVE-2022-39014 Missing Encryption of Sensitive Data vulnerability in SAP Businessobjects Business Intelligence Platform 430
Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
network
low complexity
sap CWE-311
5.3
2022-07-12 CVE-2022-29619 Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.
network
low complexity
sap
6.5
2022-07-12 CVE-2022-35169 Information Exposure vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application.
network
low complexity
sap CWE-200
6.5
2022-07-12 CVE-2022-35228 Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted.
network
sap
6.8
2022-04-12 CVE-2022-22541 Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections.
network
low complexity
sap
4.0
2022-04-12 CVE-2022-27667 Information Exposure vulnerability in SAP Businessobjects Business Intelligence Platform 430
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
network
sap CWE-200
4.3
2022-04-12 CVE-2022-27671 Information Exposure Through Sent Data vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
network
sap CWE-201
4.3
2022-04-12 CVE-2022-28213 Missing XML Validation vulnerability in SAP Businessobjects Business Intelligence Platform 420/430
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
network
low complexity
sap CWE-112
5.5