CVE-2019-0268
https://notcve.org/view.php?id=CVE-2019-0268
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source. SAP BusinessObjects Business Intelligence Platform (CMC Module), en versiones 4.10, 4.20 y 4.30, no valida de manera suficiente un documento XML recibido desde una fuente no fiable. • http://www.securityfocus.com/bid/107364 https://launchpad.support.sap.com/#/notes/2689259 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080 • CWE-91: XML Injection (aka Blind XPath Injection) •
CVE-2018-2473
https://notcve.org/view.php?id=CVE-2018-2473
SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. SAP BusinessObjects Business Intelligence Platform Server, en versiones 4.1 y 4.2, al emplear el gateway de modo de nivel 3 Web Intelligence Richclient, permite que un atacante evite que usuarios legítimos accedan a un servicio, ya sea cerrándolo inesperadamente o inundando el servicio. • http://www.securityfocus.com/bid/105903 https://launchpad.support.sap.com/#/notes/2657670 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 •
CVE-2018-2483
https://notcve.org/view.php?id=CVE-2018-2483
HTTP Verb Tampering is possible in SAP BusinessObjects Business Intelligence Platform, versions 4.1 and 4.2, Central Management Console (CMC) by changing request method. Es posible la falsificación de verbos HTTP en SAP BusinessObjects Business Intelligence Platform 4.1 y 4.2, en Central Management Console (CMC) cambiando el método de petición. • http://www.securityfocus.com/bid/105899 https://launchpad.support.sap.com/#/notes/2647714 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 • CWE-287: Improper Authentication •
CVE-2018-2446
https://notcve.org/view.php?id=CVE-2018-2446
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure. AdminTools en SAP BusinessObjects Business Intelligence, en versiones 4.1 y 4.2, permite que un usuario no autenticado lea información sensible (nombre del servidor), lo que conduce a una divulgación de información. • http://www.securityfocus.com/bid/105089 https://launchpad.support.sap.com/#/notes/2633846 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 •
CVE-2018-2442
https://notcve.org/view.php?id=CVE-2018-2442
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid. En SAP BusinessObjects Business Intelligence, en versiones 4.0, 4.1 y 4.2, mientras se visualiza un informe Web Intelligence del BI Launchpad, los detalles de la sesión de usuario capturados por una herramienta de análisis HTTP podrían reutilizarse en una página HTML mientras la sesión de usuario sigue siendo válida. • http://www.securityfocus.com/bid/105078 https://launchpad.support.sap.com/#/notes/2407193 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-352: Cross-Site Request Forgery (CSRF) •