ENG
ENG Spagobi: vulnerabilidades y CVE
ENG Spagobi tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-54795 | Media (5.4) | 0.52% | — | 21 ene 2025 | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. |
| CVE-2024-54794 | Crítica (9.1) | 13% | — | 21 ene 2025 | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. |
| CVE-2024-54792 | Media (6.1) | 0.29% | — | 21 ene 2025 | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application… |
| CVE-2013-6231 | Alta (8.8) | 9.9% | — | 10 ene 2020 | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script |
| CVE-2013-6234 | Alta (8) | 6.7% | — | 22 nov 2019 | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via… |
| CVE-2014-7296 | Media (6.8) | 1.7% | — | 8 oct 2014 | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document. |
| CVE-2013-6233 | Media (4.3) | 3.2% | — | 9 mar 2014 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata." |
| CVE-2013-6232 | Baja (3.5) | 3.6% | — | 9 mar 2014 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page. |