SAP Business Objects Business Intelligence Platform是德国思爱普(SAP)公司的一套商业智能软件和企业绩效解决方案套件。该产品具有报告生成、分析和数据可视化等功能。 SAP Business Objects Business Intelligence Platform 420版本和430版本存在注入漏洞,该漏洞源于存在代码注入漏洞,攻击者利用该漏洞可以访问额外权限允许的资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | Business Objects Business Intelligence Platform (CMC) | 420 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-23857 | 9.9 CRITICAL | Improper Access Control in SAP NetWeaver AS for Java |
| CVE-2023-27500 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27269 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-25617 | 9.0 CRITICAL | OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform |
| CVE-2023-27893 | 8.8 HIGH | Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI) |
| CVE-2023-27501 | 8.7 HIGH | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-26459 | 7.4 HIGH | Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Pla |
| CVE-2023-27498 | 7.2 HIGH | Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL) |
| CVE-2023-25615 | 6.8 MEDIUM | SQL Injection vulnerability in SAP ABAP Platform |
| CVE-2023-26461 | 6.8 MEDIUM | XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal) |
| CVE-2023-27896 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-27271 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-27270 | 6.5 MEDIUM | Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-25618 | 6.5 MEDIUM | Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-26457 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Content Server |
| CVE-2023-27895 | 6.1 MEDIUM | Information Disclosure vulnerability in SAP Authenticator for Android |
| CVE-2023-27268 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service) |
| CVE-2023-26460 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Cache Management Service) |
| CVE-2023-24526 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Classload Service) |
| CVE-2023-27894 | 5.0 MEDIUM | Sensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platform |
No comments yet