SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSap Businessobjects Business Intelligence Platform
APPSap4.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-0022CRITICAL9.9PL ✓same product
SAP BusinessObjects BI — zdalne wykonanie kodu przez uwierzytelnionego użytkownika
CVE-2023-0018CRITICAL10.0PL ✓same product
Stored XSS w SAP BusinessObjects BI Platform CMC — CVSS 10.0
CVE-2020-26831CRITICAL9.6PL ✓same product
SAP BusinessObjects BI Platform — SSRF i ujawnienie plików przez XML Injection
CVE-2020-6294CRITICAL9.1PL ✓same product
SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)
CVE-2020-6242CRITICAL9.8PL ✓same product
SAP BusinessObjects BI Platform — logowanie bez hasła do CMC (Missing Authentication)