Show filters
1,712 Total Results
Displaying 341-350 of 1,712
Sort by:
Attacker Value
Unknown
CVE-2022-39015
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2022-39013
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2022-35296
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.
0
Attacker Value
Unknown
CVE-2022-39800
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2020-19587
Disclosure Date: September 14, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.
0
Attacker Value
Unknown
CVE-2020-19586
Disclosure Date: September 14, 2022 (last updated February 24, 2025)
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
0
Attacker Value
Unknown
CVE-2022-32244
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.
0
Attacker Value
Unknown
CVE-2022-39014
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2022-35292
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries, it can be used to gain privileged permissions on a system or network leading to high impact on Confidentiality, Integrity, and Availability.
0
Attacker Value
Unknown
CVE-2022-28884
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an infinite loop when unpacking PE files. It is possible that this can crash the scanning engine.
0