SAP SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP BusinessObjects Business Intelligence Platform.
Products
Clear product- SAP 3D Visual Enterprise Viewer127 vulnerabilities
- SAP 3D Visual Enterprise Author27 vulnerabilities
- SAP Business One18 vulnerabilities
- SAP Disclosure Management13 vulnerabilities
- SAP Internet Graphics Server13 vulnerabilities
- SAP Business Objects Business Intelligence Platform12 vulnerabilities
- SAP HANA Extended Application Services12 vulnerabilities
- SAP Commerce10 vulnerabilities
- SAP Enable Now10 vulnerabilities
- SAP NetWeaver Enterprise Portal10 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform9 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)9 vulnerabilities
- SAP Adaptive Server Enterprise7 vulnerabilities
- SAP Financial Consolidation7 vulnerabilities
- SAP Internet Graphics Service7 vulnerabilities
- SAP NetWeaver AS ABAP7 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform7 vulnerabilities
- SAP Cloud Connector6 vulnerabilities
- SAP HANA6 vulnerabilities
- SAP S/4HANA6 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (BI Workspace)5 vulnerabilities
- SAP Commerce Cloud5 vulnerabilities
- SAP Host Agent5 vulnerabilities
- SAP NetWeaver (ABAP Server) and ABAP Platform5 vulnerabilities
- SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-29619MEDIUM | Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted. CWE-863Jul 12, 2022 | CVSS6.5v3.1 | EPSS0.821% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-27671MEDIUM | A CSRF token visible in the URL may possibly lead to information disclosure vulnerability. CWE-201Apr 12, 2022 | CVSS6.5v3.1 | EPSS1.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-28213HIGH | SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS. CWE-112Apr 12, 2022 | CVSS8.1v3.1 | EPSS12.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-22541MEDIUM | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access. CWE-213Apr 12, 2022 | CVSS6.5v3.1 | EPSS0.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-27667HIGH | Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure. CWE-200Apr 12, 2022 | CVSS7.5v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42061MEDIUM | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and publish these modifications to the server. It impacts the "Quick Prompt" workflow. CWE-79Dec 14, 2021 | CVSS5.4v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6251MEDIUM | Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted. CWE-200May 12, 2020 | CVSS6.5v3.1 | EPSS0.782% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6221MEDIUM | Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. CWE-79Apr 14, 2020 | CVSS5.4v3.1 | EPSS0.648% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0289HIGH | Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted. May 14, 2019 | CVSS7.1v3.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |