Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2022-26104
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
0
Attacker Value
Unknown
CVE-2019-0370
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.
0
Attacker Value
Unknown
CVE-2019-0369
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2018-2499
Disclosure Date: January 08, 2019 (last updated November 27, 2024)
A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user.
0
Attacker Value
Unknown
CVE-2018-2444
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0