Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Businessobjects Explorer
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-8316 1 Sap 1 Businessobjects Explorer 2023-12-10 5.0 MEDIUM N/A
XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrary files via the xmlParameter parameter in an explorationSpaceUpdate request.
CVE-2014-8315 1 Sap 1 Businessobjects Explorer 2023-12-10 5.0 MEDIUM N/A
polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allows remote attackers to conduct port scanning attacks via a host name and port in the cms parameter.