SAP Business Objects Web Intelligence是德国思爱普(SAP)公司的一个集中套件。用于数据报告、可视化和共享。 SAP Business Objects Web Intelligence 420版本存在跨站脚本漏洞,该漏洞源于通过URL参数可能容易受到跨站脚本(XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP BusinessObjects Web Intelligence | 420 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-42477 | 6.5 MEDIUM | Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application) |
| CVE-2023-40310 | 6.5 MEDIUM | Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import |
| CVE-2023-42473 | 5.4 MEDIUM | Missing Authorization Check In S/4HANA (Manage Withholding Tax Items) |
| CVE-2023-42475 | 4.3 MEDIUM | Information Disclosure Vulnerability in Statutory Reporting |
| CVE-2023-41365 | 4.3 MEDIUM | Information Disclosure vulnerability in SAP Business One (B1i) |
No comments yet