Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NOpengroup Unix
OSOpengroupall versionsSap Businessobjects Business Intelligence Platform
APPSap4.24.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2013-0625CRITICAL9.8⚠ KEVPL ✓same product
Adobe ColdFusion — pominięcie uwierzytelnienia bez hasła (Auth Bypass)
CVE-2011-2462CRITICAL9.8⚠ KEVPL ✓same product
RCE w komponencie U3D Adobe Reader i Acrobat — aktywnie exploitowany
CVE-2023-0022CRITICAL9.9PL ✓same product
SAP BusinessObjects BI — zdalne wykonanie kodu przez uwierzytelnionego użytkownika
CVE-2023-0018CRITICAL10.0PL ✓same product
Stored XSS w SAP BusinessObjects BI Platform CMC — CVSS 10.0
CVE-2020-26831CRITICAL9.6PL ✓same product
SAP BusinessObjects BI Platform — SSRF i ujawnienie plików przez XML Injection