CVE-2019-0251
https://notcve.org/view.php?id=CVE-2019-0251
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fiori Launchpad en SAP BusinessObjects, en versiones anteriores a la 4.2 y 4.3, no cifra lo suficiente las entradas controladas por el usuario, lo que resulta en una vulnerabilidad Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/106993 https://launchpad.support.sap.com/#/notes/2638175 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-0259
https://notcve.org/view.php?id=CVE-2019-0259
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation. SAP BusinessObjects, en versiones 4.2 y 4.3, (diferencia visual) permite que un atacante suba cualquier archivo (incluyendo archivos de script) sin una validación del formato de archivo adecuada. • http://www.securityfocus.com/bid/106997 https://launchpad.support.sap.com/#/notes/2727564 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-2473
https://notcve.org/view.php?id=CVE-2018-2473
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. SAP BusinessObjects Business Intelligence Platform Server, en versiones 4.1 y 4.2, al emplear el gateway de modo de nivel 3 Web Intelligence Richclient, permite que un atacante evite que usuarios legítimos accedan a un servicio, ya sea cerrándolo inesperadamente o inundando el servicio. • http://www.securityfocus.com/bid/105903 https://launchpad.support.sap.com/#/notes/2657670 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 •
CVE-2018-2479
https://notcve.org/view.php?id=CVE-2018-2479
SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP BusinessObjects Business Intelligence Platform (BIWorkspace) 4.1 y 4.2 no cifra lo suficiente las entradas controladas por el usuario, lo que resulta en una vulnerabilidad Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/105902 https://launchpad.support.sap.com/#/notes/2676094 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-2483
https://notcve.org/view.php?id=CVE-2018-2483
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method. Es posible la falsificación de verbos HTTP en SAP BusinessObjects Business Intelligence Platform 4.1 y 4.2, en Central Management Console (CMC) cambiando el método de petición. • http://www.securityfocus.com/bid/105899 https://launchpad.support.sap.com/#/notes/2647714 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 • CWE-287: Improper Authentication •