Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2018-2483

Disclosure Date: November 13, 2018 (last updated November 27, 2024)
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.
0
Attacker Value
Unknown

CVE-2018-2471

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown

CVE-2018-2445

Disclosure Date: August 14, 2018 (last updated November 27, 2024)
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown

CVE-2018-2442

Disclosure Date: August 14, 2018 (last updated November 27, 2024)
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
0
Attacker Value
Unknown

CVE-2018-2446

Disclosure Date: August 14, 2018 (last updated November 27, 2024)
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
Attacker Value
Unknown

CVE-2018-2427

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
0
Attacker Value
Unknown

CVE-2018-2431

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2018-2432

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
Attacker Value
Unknown

CVE-2018-2397

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
0