SAP BusinessObjects Business Intelligence Platform是德国思爱普(SAP)公司的一款完备的商务分析平台。该平台集市场领先的 SAP 数据整合产品、数据管理产品和商务智能 (BI) 产品于一身,可消除系统集成难题,快速、轻松地部署高性能的商务分析软件。 SAP BusinessObjects Business Intelligence Platform 420版本和430版本存在信息泄露漏洞,该漏洞源于允许攻击者注入任意值作为CMS参数以在内部网络上执行查找,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | BusinessObjects Business Intelligence Platform (Web Services) | 420 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25616 | 9.9 CRITICAL | Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC) |
| CVE-2023-23857 | 9.9 CRITICAL | Improper Access Control in SAP NetWeaver AS for Java |
| CVE-2023-27500 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27269 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-25617 | 9.0 CRITICAL | OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform |
| CVE-2023-27893 | 8.8 HIGH | Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI) |
| CVE-2023-27501 | 8.7 HIGH | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-26459 | 7.4 HIGH | Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Pla |
| CVE-2023-27498 | 7.2 HIGH | Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL) |
| CVE-2023-26461 | 6.8 MEDIUM | XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal) |
| CVE-2023-25615 | 6.8 MEDIUM | SQL Injection vulnerability in SAP ABAP Platform |
| CVE-2023-27270 | 6.5 MEDIUM | Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27271 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-25618 | 6.5 MEDIUM | Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27896 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-27895 | 6.1 MEDIUM | Information Disclosure vulnerability in SAP Authenticator for Android |
| CVE-2023-26457 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Content Server |
| CVE-2023-27268 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service) |
| CVE-2023-26460 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Cache Management Service) |
| CVE-2023-24526 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Classload Service) |
No comments yet