SAP SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP Business Objects Business Intelligence Platform.
Products
Clear product- SAP 3D Visual Enterprise Viewer127 vulnerabilities
- SAP 3D Visual Enterprise Author27 vulnerabilities
- SAP Business One18 vulnerabilities
- SAP Disclosure Management13 vulnerabilities
- SAP Internet Graphics Server13 vulnerabilities
- SAP Business Objects Business Intelligence Platform12 vulnerabilities
- SAP HANA Extended Application Services12 vulnerabilities
- SAP Commerce10 vulnerabilities
- SAP Enable Now10 vulnerabilities
- SAP NetWeaver Enterprise Portal10 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform9 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)9 vulnerabilities
- SAP Adaptive Server Enterprise7 vulnerabilities
- SAP Financial Consolidation7 vulnerabilities
- SAP Internet Graphics Service7 vulnerabilities
- SAP NetWeaver AS ABAP7 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform7 vulnerabilities
- SAP Cloud Connector6 vulnerabilities
- SAP HANA6 vulnerabilities
- SAP S/4HANA6 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (BI Workspace)5 vulnerabilities
- SAP Commerce Cloud5 vulnerabilities
- SAP Host Agent5 vulnerabilities
- SAP NetWeaver (ABAP Server) and ABAP Platform5 vulnerabilities
- SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-6220MEDIUM | BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active. CWE-79Jun 6, 2022 | CVSS4.7v3.1 | EPSS0.489% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-24398MEDIUM | Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access information which would otherwise be restricted. CWE-200Mar 8, 2022 | CVSS6.5v3.1 | EPSS0.802% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6294CRITICAL | Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity. CWE-306Aug 12, 2020 | CVSS9.1v3.1 | EPSS1.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6269MEDIUM | Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure. CWE-200Jun 10, 2020 | CVSS6.5v3.1 | EPSS0.789% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6247HIGH | SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system availability. CWE-20May 12, 2020 | CVSS7.5v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6245MEDIUM | SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers. | CVSS6.7v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6211MEDIUM | SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability. CWE-601Apr 14, 2020 | CVSS6.1v3.1 | EPSS0.655% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6195CRITICAL | SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative rights to the attacker to read/modify delete the data and rights within the system. | CVSS9.8v3.1 | EPSS0.628% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6237HIGH | Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure. CWE-200Apr 14, 2020 | CVSS7.5v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6223MEDIUM | The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoofing. CWE-601Apr 14, 2020 | CVSS6.1v3.1 | EPSS0.655% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6218MEDIUM | Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information that should otherwise be restricted, leading to Information Disclosure. CWE-200Apr 14, 2020 | CVSS5.0v3.1 | EPSS0.905% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-2397MEDIUM | In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting. CWE-79Mar 14, 2018 | CVSS5.4v3.0 | EPSS0.934% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |