Businessobjects Business Intelligence Platform
Vendor:
First CVE: Mar 14, 2018 · Active for 8 years
91
Total CVEs
More Total CVEs than 99% of tracked products
10.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Businessobjects Business Intelligence Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2018
8 years ago
Most Recent CVE
Feb 10, 2026
167 days ago
CVE Severity & Scoring
Businessobjects Business Intelligence Platform91 CVEs
64%
27%
9%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (4.4%)
Network86 (94.5%)
Unknown0 (0.0%)
Physical1 (1.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low90 (98.9%)
High1 (1.1%)
Unknown0 (0.0%)
User Interaction
None52 (57.1%)
Unknown0 (0.0%)
Required39 (42.9%)
Privileges Required
Low45 (49.5%)
High11 (12.1%)
None35 (38.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (91 CVEs).
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41730CRITICAL In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a logon token using a REST endpoint | Aug 13, 2024 | 9.8 | 73 | NO | NO |
CVE-2020-6308MEDIUM SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perfo | Oct 20, 2020 | 5.3 | 62 | NO | YES |
CVE-2022-28213HIGH When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an u | Apr 12, 2022 | 8.1 | 35 | NO | YES |
CVE-2020-26831CRITICAL SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML | Dec 9, 2020 | 9.6 | 30 | NO | NO |
CVE-2020-6242CRITICAL SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without pas | May 12, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-24530CRITICAL SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application ov | Feb 14, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-0022HIGH SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the netwo | Jan 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-41267HIGH SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating syst | Dec 13, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-25617HIGH SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated us | Mar 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-25616HIGH In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow | Mar 14, 2023 | 8.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (91 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 96th percentile
ExploitDB
1 CVE
1.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (91 CVEs).
Media Mentions
Signals from CVEs in this product scope (91 CVEs).
Top CNAs Publishing CVEs For Businessobjects Business Intelligence Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| enterprise_440 | 1 | 9.8 | 75.9% | 0 | 0 |
| enterprise_430 | 1 | 9.8 | 75.9% | 0 | 0 |
| enterprise_420 | 2 | 4.3 | 0.4% | 0 | 0 |
| 440 | 6 | 5.4 | 0.3% | 0 | 0 |
| 4.30 | 3 | 6.8 | 1.1% | 0 | 0 |
| 430 | 42 | 6.7 | 0.8% | 0 | 1 |
| 4.3 | 5 | 7.5 | 13.1% | 0 | 1 |
| 4.20 | 4 | 7.0 | 1.3% | 0 | 0 |
| 420 | 30 | 6.8 | 1.0% | 0 | 1 |
| 4.2 | 32 | 6.1 | 2.2% | 0 | 1 |
| 4.10 | 3 | 6.8 | 1.3% | 0 | 0 |
| 4.1 | 21 | 6.0 | 2.3% | 0 | 1 |
| 4.00 | 1 | 5.4 | 0.9% | 0 | 0 |
| 4.0 | 6 | 5.7 | 0.7% | 0 | 0 |
| 2.3 | 1 | 9.8 | 0.8% | 0 | 0 |
| 2.2 | 1 | 9.8 | 0.8% | 0 | 0 |
| 2.1 | 1 | 9.8 | 0.8% | 0 | 0 |
| 2027 | 5 | 7.0 | 0.3% | 0 | 0 |
| 2025 | 10 | 6.8 | 0.3% | 0 | 0 |
| 2.0 | 1 | 9.8 | 0.8% | 0 | 0 |