Businessobjects Business Intelligence

Vendor:

First CVE: Jul 10, 2018 · Active for 8 years

45
Total CVEs
More Total CVEs than 98% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Businessobjects Business Intelligence over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2018
8 years ago
Most Recent CVE
Jun 10, 2025
413 days ago

CVE Severity & Scoring

Businessobjects Business Intelligence45 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local2 (4.4%)
Network41 (91.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (4.4%)
Attack Complexity
Low44 (97.8%)
High1 (2.2%)
Unknown0 (0.0%)
User Interaction
None27 (60.0%)
Unknown0 (0.0%)
Required18 (40.0%)
Privileges Required
Low24 (53.3%)
High3 (6.7%)
None18 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decry
Apr 11, 20239.837NONO
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive informatio
Sep 12, 20239.928NONO
In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object i
Nov 8, 20228.828NONO
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the ap
Aug 14, 20189.628NONO
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code th
Jul 10, 20188.827NONO
SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the net
Aug 10, 20228.226NONO
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
Mar 12, 20198.126NONO
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP ana
Aug 14, 20188.826NONO
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the
Aug 8, 20239.025NONO
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an informat
Aug 14, 20187.525NONO

Exploit Exposure

Signals from CVEs in this product scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (45 CVEs).

Media Mentions

Signals from CVEs in this product scope (45 CVEs).

Top CNAs Publishing CVEs For Businessobjects Business Intelligence

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
430236.81.1%00
4.386.41.1%00
4.2036.81.3%00
420236.61.1%00
4.2176.71.1%00
4.1036.81.3%00
41025.80.7%00
4.1136.61.1%00
4.018.80.7%00
202717.60.4%00
202527.00.4%00