Page 21 of 110 results (0.008 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method. Es posible la falsificación de verbos HTTP en SAP BusinessObjects Business Intelligence Platform 4.1 y 4.2, en Central Management Console (CMC) cambiando el método de petición. • http://www.securityfocus.com/bid/105899 https://launchpad.support.sap.com/#/notes/2647714 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted. En ciertas condiciones, SAP BusinessObjects Business Intelligence Platform, en versiones 4.10 y 4.20, permite que un atacante acceda a información que normalmente estaría restringida. • http://www.securityfocus.com/bid/105530 https://launchpad.support.sap.com/#/notes/2654905 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure. AdminTools en SAP BusinessObjects Business Intelligence, en versiones 4.1 y 4.2, permite que un usuario no autenticado lea información sensible (nombre del servidor), lo que conduce a una divulgación de información. • http://www.securityfocus.com/bid/105089 https://launchpad.support.sap.com/#/notes/2633846 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 •

CVSS: 8.8EPSS: 0%CPEs: 8EXPL: 0

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid. En SAP BusinessObjects Business Intelligence, en versiones 4.0, 4.1 y 4.2, mientras se visualiza un informe Web Intelligence del BI Launchpad, los detalles de la sesión de usuario capturados por una herramienta de análisis HTTP podrían reutilizarse en una página HTML mientras la sesión de usuario sigue siendo válida. • http://www.securityfocus.com/bid/105078 https://launchpad.support.sap.com/#/notes/2407193 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.6EPSS: 0%CPEs: 2EXPL: 0

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability. AdminTools en SAP BusinessObjects Business Intelligence, en versiones 4.1 y 4.2, permite que un atacante manipule la aplicación vulnerable para enviar peticiones manipuladas en nombre de la aplicación, lo que resulta en una vulnerabilidad de SSRF (Server-Side Request Forgery). • http://www.securityfocus.com/bid/105064 https://launchpad.support.sap.com/#/notes/2630018 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-918: Server-Side Request Forgery (SSRF) •