Business Objects Business Intelligence Platform
18 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Business Objects Business Intelligence Platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Business Objects Business Intelligence Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High2
- Medium10
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Business Objects Business Intelligence Platform.
- CVE-2024-41731Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform3.1
- CVE-2024-28166Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform3.7
- CVE-2024-42375Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform4.3
- CVE-2024-41730Missing Authentication check in SAP BusinessObjects Business Intelligence Platform9.8
- CVE-2023-42478Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform7.5
- CVE-2023-25617OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)9.0
- CVE-2023-25616Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)9.9
- CVE-2023-23856In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom app...4.3
- CVE-2023-0015Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)4.6
- CVE-2022-41267SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enablin...9.9
- CVE-2022-41263Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the d...4.3
- CVE-2022-31596Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - ver...6.0
- CVE-2022-39013Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable lead...7.6
- CVE-2022-39015Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.6.5
- CVE-2022-31598Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an...5.4
Product grouping is registry-driven, with AI assist and human review. How it works