SAP BusinessObjects Business Intelligence Platform是德国SAP公司的一个商业智能与分析平台。 SAP BusinessObjects Business Intelligence Platform存在加密问题漏洞,该漏洞源于使用硬编码加密密钥存储敏感凭据,可能导致具有高权限和本地访问权限的攻击者检索并解密存储的凭据,获取敏感认证数据并修改受保护信息,对机密性和完整性造成高影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP BusinessObjects Business Intelligence Platform (Central Management Server) | ENTERPRISE 430 |
affected |
2025 |
affected | ||
2027 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP BusinessObjects Business Intelligence Platform (Central Management Server) | ENTERPRISE 430 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58231 | 10.0 CRITICAL | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) |
| CVE-2026-34265 | 9.8 CRITICAL | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Plat |
| CVE-2026-44758 | 9.1 CRITICAL | Code Injection vulnerability in Manufacturing Integration and Intelligence |
| CVE-2026-58243 | 8.8 HIGH | Privilege Escalation vulnerability in SAP ABAP Developer Tools |
| CVE-2026-44763 | 7.6 HIGH | Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence |
| CVE-2026-44764 | 7.3 HIGH | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-44765 | 7.3 HIGH | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-58230 | 7.0 HIGH | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58248 | 6.5 MEDIUM | XML External Entity Injection in SAP BusinessObjects Business Intelligence |
| CVE-2026-66760 | 6.4 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66770 | 6.3 MEDIUM | SQL Injection vulnerability in SAP Social Intelligence |
| CVE-2026-66779 | 6.3 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP |
| CVE-2026-58235 | 6.3 MEDIUM | Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) |
| CVE-2026-66771 | 6.1 MEDIUM | Cross Site Scripting (XSS) vulnerability in SAPUI5 |
| CVE-2026-66773 | 5.9 MEDIUM | Server-controlled `__next` URL is not checking cross-origin |
| CVE-2026-58237 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58238 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66777 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66776 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58236 | 5.5 MEDIUM | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Pl |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet