Vulnerabilities > SAP > Businessobjects Business Intelligence > 430

DATE CVE VULNERABILITY TITLE RISK
2023-03-14 CVE-2023-27896 Server-Side Request Forgery (SSRF) vulnerability in SAP Businessobjects Business Intelligence 420/430
In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.
network
low complexity
sap CWE-918
7.5
2022-10-11 CVE-2022-35296 Information Exposure vulnerability in SAP Businessobjects Business Intelligence 420/430
Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.
network
low complexity
sap CWE-200
4.9
2022-10-11 CVE-2022-39800 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 420/430
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network.
network
low complexity
sap CWE-79
6.1
2022-10-11 CVE-2022-41206 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 420/430
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console.
network
low complexity
sap CWE-79
5.4
2022-08-10 CVE-2022-32245 Cleartext Transmission of Sensitive Information vulnerability in SAP Businessobjects Business Intelligence 420/430
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network.
network
low complexity
sap CWE-319
8.2
2022-05-11 CVE-2022-28214 Cleartext Storage of Sensitive Information vulnerability in SAP products
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs.
local
low complexity
sap CWE-312
4.6
2021-09-15 CVE-2021-33696 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 420/430
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.
network
sap CWE-79
3.5
2021-09-15 CVE-2021-33697 Improper Privilege Management vulnerability in SAP Businessobjects Business Intelligence 420/430
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
network
sap CWE-269
5.8
2021-02-09 CVE-2021-21444 Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP Businessobjects Business Intelligence 410/420/430
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents.
network
sap CWE-1021
5.8