Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown
CVE-2019-0262
Disclosure Date: February 15, 2019 (last updated November 27, 2024)
SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2473
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
0
Attacker Value
Unknown
CVE-2018-2479
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2483
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.
0
Attacker Value
Unknown
CVE-2018-2472
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2467
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser such as Chrome the system returns an error with the path of the used application server.
0
Attacker Value
Unknown
CVE-2018-2471
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2018-2445
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2442
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
0
Attacker Value
Unknown
CVE-2018-2446
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
0