Known Vulnerabilities for Businessobjects by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Businessobjects" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-0303 | SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp... | 6.1 - MEDIUM | 2019-06-14 | 2019-06-18 |
| CVE-2019-0289 | Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows... | 7.1 - HIGH | 2019-05-14 | 2020-08-24 |
| CVE-2019-0287 | Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3... | 7.6 - HIGH | 2019-05-14 | 2020-08-24 |
| CVE-2019-0259 | SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files)... | 9.8 - CRITICAL | 2019-02-15 | 2019-02-20 |
| CVE-2019-0251 | The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs,... | 6.1 - MEDIUM | 2019-02-15 | 2019-02-19 |
| CVE-2018-2408 | Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad... | 7.3 - HIGH | 2018-04-10 | 2019-10-09 |
| CVE-2017-16683 | Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent l... | 6.5 - MEDIUM | 2017-12-12 | 2017-12-21 |
| CVE-2015-7730 | SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to... | 10 - HIGH | 2015-10-15 | 2015-10-16 |
| CVE-2014-8308 | Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote ... | 4.3 - MEDIUM | 2014-10-16 | 2018-10-09 |
| CVE-2014-3134 | Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to inject... | 4.3 - MEDIUM | 2014-04-30 | 2014-05-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects | 4.30 | All | All | All |
| Application | Sap | Businessobjects | 4.3 | All | All | All |
| Application | Sap | Businessobjects | 4.20 | All | All | All |
| Application | Sap | Businessobjects | 4.2 | All | All | All |
| Application | Sap | Businessobjects | 4.10 | All | All | All |
| Application | Sap | Businessobjects | 4.0 | All | All | All |
| Application | Sap | Businessobjects | - | All | All | All |