VendorsSAPbusinessobjects_business_intelligence_platformall versions
Vulnerabilities

SAP BusinessObjects Business Intelligence Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2023-0018
Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
Published 2023-01-10 · Modified
10.0EPSS 0.005
CVE-2023-0022
Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)
Published 2023-01-10 · Modified
9.9EPSS 0.007
CVE-2020-6242
SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Authentication Check.
Published 2020-05-12 · Modified
9.8EPSS 0.008
CVE-2020-6195
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system.
Published 2020-04-14 · Modified
9.8EPSS 0.006
CVE-2020-26831
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
Published 2020-12-09 · Modified
9.6EPSS 0.011
CVE-2024-28165
Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Published 2024-05-14 · Analyzed
9.3EPSS 0.006
CVE-2020-6294
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
Published 2020-08-12 · Modified
9.1EPSS 0.015
CVE-2020-6219
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized execution of arbitrary commands, leading to Deserialization of Untrusted Data.
Published 2020-04-14 · Modified
9.1EPSS 0.013
CVE-2023-24530
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.
Published 2023-02-14 · Modified
9.1EPSS 0.006
CVE-2025-0061
Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Published 2025-01-14 · Analyzed
9.1EPSS 0.005
CVE-2022-35228
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
Published 2022-07-12 · Modified
8.8EPSS 0.006
CVE-2019-0398
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
Published 2019-12-11 · Modified
8.8EPSS 0.005
CVE-2023-42472
Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
Published 2023-09-12 · Modified
8.7EPSS 0.006
CVE-2025-0064
Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)
Published 2025-02-11 · Analyzed
8.7EPSS 0.004
CVE-2023-0020
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.
Published 2023-02-14 · Modified
8.5EPSS 0.005
CVE-2022-28213
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS.
Published 2022-04-12 · Modified
8.11 PoCEPSS 0.125
CVE-2026-0508
Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform
Published 2026-02-10 · Analyzed
8.1EPSS 0.003
CVE-2018-2471
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.
Published 2018-10-09 · Modified
7.5EPSS 0.017
CVE-2022-27667
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Published 2022-04-12 · Modified
7.5EPSS 0.014
CVE-2021-40500
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.
Published 2021-10-12 · Modified
7.5EPSS 0.013
CVE-2020-6237
Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Published 2020-04-14 · Modified
7.5EPSS 0.011
CVE-2019-0352
In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the dynamic pages even after logout.
Published 2019-09-10 · Modified
7.5EPSS 0.011
CVE-2020-6247
SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system availability.
Published 2020-05-12 · Modified
7.5EPSS 0.010
CVE-2020-6227
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files.
Published 2020-04-14 · Modified
7.5EPSS 0.009
CVE-2023-27271
Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platform
Published 2023-03-14 · Modified
7.5EPSS 0.006
CVE-2026-0485
Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
Published 2026-02-10 · Analyzed
7.5EPSS 0.004
CVE-2026-0490
Denial of service (DOS) in SAP BusinessObjects BI Platform
Published 2026-02-10 · Analyzed
7.5EPSS 0.004
CVE-2019-0396
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.
Published 2019-11-13 · Modified
7.1EPSS 0.009
CVE-2025-31332
Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform
Published 2025-04-08 · Analyzed
7.1EPSS 0.002
CVE-2020-6245
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
Published 2020-05-12 · Modified
6.7EPSS 0.003
CVE-2022-27671
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Published 2022-04-12 · Modified
6.5EPSS 0.013
CVE-2022-29619
Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.
Published 2022-07-12 · Modified
6.5EPSS 0.009
CVE-2022-22541
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access.
Published 2022-04-12 · Modified
6.5EPSS 0.008
CVE-2020-6269
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Published 2020-06-10 · Modified
6.5EPSS 0.008
CVE-2020-6251
Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.
Published 2020-05-12 · Modified
6.5EPSS 0.008
CVE-2022-35169
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application.
Published 2022-07-12 · Modified
6.5EPSS 0.007
CVE-2025-0060
Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Published 2025-01-14 · Analyzed
6.5EPSS 0.004
CVE-2026-24324
Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)
Published 2026-02-10 · Analyzed
6.5EPSS 0.003
CVE-2022-28216
SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access certain reports causing a limited impact on confidentiality of the application data.
Published 2022-04-12 · Modified
6.1EPSS 0.008
CVE-2020-6281
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
Published 2020-07-14 · Modified
6.1EPSS 0.008
1 / 2Next →