Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap business objects business intelligence platform 420 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-25617
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom applicati...
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
1 Article
8.8
CVSSv3
CVE-2023-25616
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an malicious user to gain access to resources that are allowed by extra privileges. Successful atta...
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
1 Article
8.8
CVSSv3
CVE-2022-41267
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the malicious user to take full control of the system causing a high impact on co...
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
7.6
CVSSv3
CVE-2023-42478
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an malicious user to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
7.6
CVSSv3
CVE-2022-39013
Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the malicious user to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availab...
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
6.5
CVSSv3
CVE-2022-39015
Under certain conditions, BOE AdminTools/ BOE SDK allows an malicious user to access information which would otherwise be restricted.
Sap Business Objects Business Intelligence Platform 430
Sap Business Objects Business Intelligence Platform 420
6.5
CVSSv3
CVE-2022-29619
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.
Sap Businessobjects Business Intelligence Platform 420
Sap Businessobjects Business Intelligence Platform 430
6.5
CVSSv3
CVE-2022-24398
Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated malicious user to access information which would otherwise be restricted.
Sap Business Objects Business Intelligence Platform 420
Sap Business Objects Business Intelligence Platform 430
6.1
CVSSv3
CVE-2021-21444
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking ...
Sap Businessobjects Business Intelligence 410
Sap Businessobjects Business Intelligence 420
Sap Businessobjects Business Intelligence 430
5.4
CVSSv3
CVE-2023-0015
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vuln...
Sap Business Objects Business Intelligence Platform 420
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »