Show filters
1,712 Total Results
Displaying 331-340 of 1,712
Sort by:
Attacker Value
Unknown
CVE-2022-41263
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.
0
Attacker Value
Unknown
CVE-2022-31596
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database.
A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.
0
Attacker Value
Unknown
CVE-2022-41735
Disclosure Date: December 07, 2022 (last updated February 24, 2025)
IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 65687.
0
Attacker Value
Unknown
CVE-2022-38390
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.
0
Attacker Value
Unknown
CVE-2022-21794
Disclosure Date: November 11, 2022 (last updated February 24, 2025)
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-41066
Disclosure Date: November 09, 2022 (last updated January 11, 2025)
Microsoft Business Central Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2022-41203
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted data vulnerability. This could highly compromise the Confidentiality, Integrity, and Availability of the system.
0
Attacker Value
Unknown
CVE-2022-35279
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."
0
Attacker Value
Unknown
CVE-2022-21609
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server). The supported version that is affected is 5.9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown
CVE-2022-41206
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.
0