SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSap Businessobjects Business Intelligence Platform
APPSap420430
Related vulnerabilities
Stored XSS w SAP BusinessObjects BI Platform CMC — CVSS 10.0
SAP BusinessObjects BI Platform — SSRF i ujawnienie plików przez XML Injection
SAP BusinessObjects BI Platform – brak uwierzytelnienia w komponencie Xvfb (Unix)
SAP BusinessObjects BI Platform — logowanie bez hasła do CMC (Missing Authentication)
SAP BusinessObjects BI Platform CMC ujawnia hasło w plaintext w odpowiedzi HTTP