Known Vulnerabilities for Businessobjects by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Businessobjects" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-27683 json | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payload... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2023-40623 json | SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under te... | 7.1 - HIGH | 2023-09-12 | 2023-09-13 |
| CVE-2023-28764 json | SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the... | 5.9 - MEDIUM | 2023-05-09 | 2023-05-12 |
| CVE-2022-28214 json | During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication crede... | 7.8 - HIGH | 2022-05-11 | 2022-05-19 |
| CVE-2019-0303 json | SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp... | 6.1 - MEDIUM | 2019-06-14 | 2019-06-18 |
| CVE-2019-0289 json | Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows... | 7.1 - HIGH | 2019-05-14 | 2020-08-24 |
| CVE-2019-0287 json | Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3... | 7.6 - HIGH | 2019-05-14 | 2020-08-24 |
| CVE-2019-0259 json | SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files)... | 9.8 - CRITICAL | 2019-02-15 | 2019-02-20 |
| CVE-2019-0251 json | The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs,... | 6.1 - MEDIUM | 2019-02-15 | 2019-02-19 |
| CVE-2018-2408 json | Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad... | 7.3 - HIGH | 2018-04-10 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Businessobjects | 4.30 | |||
| Application | Sap | Businessobjects | 4.3 | |||
| Application | Sap | Businessobjects | 4.20 | |||
| Application | Sap | Businessobjects | 4.2 | |||
| Application | Sap | Businessobjects | 4.10 | |||
| Application | Sap | Businessobjects | 4.0 | |||
| Application | Sap | Businessobjects | - |