Business objects business intelligence platform
This hub aggregates every CVE we track for Business objects business intelligence platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
4
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM10CRITICAL4LOW2HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Business objects business intelligence platform.
- CVE-2024-41731Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform3.1
- CVE-2024-28166Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform3.7
- CVE-2024-42375Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform4.3
- CVE-2024-41730Missing Authentication check in SAP BusinessObjects Business Intelligence Platform9.8
- CVE-2023-42478Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform7.5
- CVE-2023-25617OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)9.0
- CVE-2023-25616Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)9.9
- CVE-2023-23856In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom app...4.3
- CVE-2023-0015Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)4.6
- CVE-2022-41267SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enablin...9.9
- CVE-2022-41263Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the d...4.3
- CVE-2022-31596Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - ver...6.0
- CVE-2022-39015Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.6.5
- CVE-2022-39013Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable lead...7.6
- CVE-2022-31598Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an...5.4
Product normalization is registry-driven with AI assist and human review. How it works