Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Businessobjects Bi Platform
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0262 1 Sap 1 Businessobjects Bi Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2479 1 Sap 1 Businessobjects Bi Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2472 1 Sap 1 Businessobjects Bi Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2467 1 Sap 1 Businessobjects Bi Platform 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser such as Chrome the system returns an error with the path of the used application server.