Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-6281

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
Attacker Value
Unknown

CVE-2020-6269

Disclosure Date: June 10, 2020 (last updated November 28, 2024)
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Attacker Value
Unknown

CVE-2020-6245

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
Attacker Value
Unknown

CVE-2020-6257

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2020-6251

Disclosure Date: May 12, 2020 (last updated November 27, 2024)
Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.
Attacker Value
Unknown

CVE-2020-6247

Disclosure Date: May 12, 2020 (last updated November 27, 2024)
SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system availability.
Attacker Value
Unknown

CVE-2020-6211

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
Attacker Value
Unknown

CVE-2020-6195

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.
Attacker Value
Unknown

CVE-2020-6216

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2020-6222

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.