Filtered by vendor Sap Subscriptions
Filtered by product Businessobjects Business Intelligence Subscriptions
Total 43 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-28762 1 Sap 1 Businessobjects Business Intelligence 2024-08-02 9.1 Critical
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.
CVE-2023-27896 1 Sap 1 Businessobjects Business Intelligence 2024-08-02 6.5 Medium
In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.
CVE-2023-27894 1 Sap 1 Businessobjects Business Intelligence 2024-08-02 5 Medium
SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.