Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2018-2397
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2015-7730
Disclosure Date: October 15, 2015 (last updated October 05, 2023)
SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.
0
Attacker Value
Unknown
CVE-2015-2076
Disclosure Date: February 27, 2015 (last updated October 05, 2023)
The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.
0
Attacker Value
Unknown
CVE-2015-2075
Disclosure Date: February 27, 2015 (last updated October 05, 2023)
SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.
0
Attacker Value
Unknown
CVE-2014-8310
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.
0
Attacker Value
Unknown
CVE-2014-8308
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-8311
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.
0
Attacker Value
Unknown
CVE-2014-8309
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service.
0