Page 7 of 40 results (0.007 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP BusinessObjects Business Intelligence Platform 4.20 y 4.20 (cliente Web Intelligence DHTML) no cifra lo suficiente las entradas controladas por el usuario, lo que resulta en una vulnerabilidad Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/105531 https://launchpad.support.sap.com/#/notes/2667103 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser such as Chrome the system returns an error with the path of the used application server. En Software Development Kit en SAP BusinessObjects BI Platform Servers en versiones 4.1 y 4.2, el uso de una URL especialmente manipulada en un navegador web como Chrome hace que el sistema devuelva un error con la ruta del servidor de aplicación empleado. • http://www.securityfocus.com/bid/105544 https://launchpad.support.sap.com/#/notes/2623618 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure. AdminTools en SAP BusinessObjects Business Intelligence, en versiones 4.1 y 4.2, permite que un usuario no autenticado lea información sensible (nombre del servidor), lo que conduce a una divulgación de información. • http://www.securityfocus.com/bid/105089 https://launchpad.support.sap.com/#/notes/2633846 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 •

CVSS: 8.8EPSS: 0%CPEs: 8EXPL: 0

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid. En SAP BusinessObjects Business Intelligence, en versiones 4.0, 4.1 y 4.2, mientras se visualiza un informe Web Intelligence del BI Launchpad, los detalles de la sesión de usuario capturados por una herramienta de análisis HTTP podrían reutilizarse en una página HTML mientras la sesión de usuario sigue siendo válida. • http://www.securityfocus.com/bid/105078 https://launchpad.support.sap.com/#/notes/2407193 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.6EPSS: 0%CPEs: 2EXPL: 0

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability. AdminTools en SAP BusinessObjects Business Intelligence, en versiones 4.1 y 4.2, permite que un atacante manipule la aplicación vulnerable para enviar peticiones manipuladas en nombre de la aplicación, lo que resulta en una vulnerabilidad de SSRF (Server-Side Request Forgery). • http://www.securityfocus.com/bid/105064 https://launchpad.support.sap.com/#/notes/2630018 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-918: Server-Side Request Forgery (SSRF) •