Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown
CVE-2018-2483
Disclosure Date: November 13, 2018 (last updated November 27, 2024)
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method.
0
Attacker Value
Unknown
CVE-2018-2471
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2018-2445
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2442
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
0
Attacker Value
Unknown
CVE-2018-2446
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
0
Attacker Value
Unknown
CVE-2018-2427
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
0
Attacker Value
Unknown
CVE-2018-2431
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2432
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
0
Attacker Value
Unknown
CVE-2018-2397
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
0