Showing 3 vulnerabilities on this page for BusinessObjects Business Intelligence Platform (Web Services)

Signals CISA KEV Ransomware Nuclei
SAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Sensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platform

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting

CWE-200Mar 14, 2023
CVSS5.0v3.1EPSS0.617%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platform

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

CWE-918Mar 14, 2023
CVSS6.5v3.1EPSS0.524%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platform

In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability.

CWE-918Mar 14, 2023
CVSS6.5v3.1EPSS0.57%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX