Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.14% | — | SAP Businessobjects Business Intelligence Platform | 11/6/2024 | 17/6/2026 | On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote… | |
| Analizada | Media (4.3) | 0.24% | — | SAP Businessobjects Business Intelligence Platform | 14/5/2024 | 17/6/2026 | SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and… | |
| Analizada | Crítica (9.3) | 0.56% | — | SAP Businessobjects Business Intelligence Platform | 14/5/2024 | 17/6/2026 | SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application | |
| Analizada | Media (6.5) | 0.42% | — | SAP Businessobjects WEB Intelligence | 9/4/2024 | 17/6/2026 | Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application. | |
| Modificada | Media (6.8) | 0.57% | — | SAP Businessobjects WEB Intelligence | 12/12/2023 | 17/6/2026 | SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to.… | |
| Modificada | Media (5.4) | 0.33% | — | SAP Businessobjects WEB Intelligence | 10/10/2023 | 17/6/2026 | SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information. | |
| Modificada | Alta (7.1) | 0.44% | — | SAP Businessobjects | 12/9/2023 | 17/6/2026 | SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity… | |
| Modificada | Crítica (9.9) | 0.65% | — | SAP Businessobjects Business Intelligence | 12/9/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on… | |
| Modificada | Alta (7.3) | 0.60% | — | SAP Businessobjects Business Intelligence Platform | 12/9/2023 | 17/6/2026 | Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request,… | |
| Modificada | Media (5.3) | 0.52% | — | SAP Businessobjects Business Intelligence | 12/9/2023 | 17/6/2026 | Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity. | |
| Modificada | Media (4.4) | 0.12% | — | SAP Businessobjects Business Intelligence | 8/8/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to get access to user credentials. For a successful attack, the attacker needs to have local access to… | |
| Modificada | Crítica (9) | 0.27% | — | SAP Businessobjects Business Intelligence | 8/8/2023 | 17/6/2026 | SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality,… | |
| Modificada | Alta (7.5) | 0.58% | — | SAP Businessobjects Business Intelligence | 11/7/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss… | |
| Modificada | Media (6.1) | 0.46% | — | SAP Businessobjects Business Intelligence | 9/5/2023 | 17/6/2026 | Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality… | |
| Modificada | Media (5) | 0.47% | — | SAP Businessobjects Business Intelligence | 9/5/2023 | 17/6/2026 | Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Businessobjects Business Intelligence | 9/5/2023 | 17/6/2026 | Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality… | |
| Modificada | Alta (7.6) | 0.46% | — | SAP Businessobjects Business Intelligence | 9/5/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and availability of the application. | |
| Modificada | Media (5.9) | 0.51% | — | SAP Businessobjects | 9/5/2023 | 17/6/2026 | SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact… | |
| Modificada | Alta (7.2) | 0.71% | — | SAP Businessobjects Business Intelligence | 9/5/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and… | |
| Modificada | Crítica (9.8) | 15% | — | SAP Businessobjects Business Intelligence | 11/4/2023 | 17/6/2026 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can… | |
| Modificada | Alta (7.5) | 0.52% | — | SAP Businessobjects Business Intelligence | 14/3/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability. | |
| Modificada | Media (5.3) | 0.62% | — | SAP Businessobjects Business Intelligence | 14/3/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine… | |
| Modificada | Alta (7.5) | 0.57% | — | SAP Businessobjects Business Intelligence Platform | 14/3/2023 | 17/6/2026 | In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high impact on availability. | |
| Modificada | Crítica (9.1) | 0.56% | — | SAP Businessobjects Business Intelligence Platform | 14/2/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high… | |
| Modificada | Alta (7.1) | 0.52% | — | SAP Businessobjects Business Intelligence Platform | 14/2/2023 | 17/6/2026 | SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application. |