📦

businessobjects

Vendor: sap

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 2 Remote Access
Total CVEs 59 Total Indexed
Avg. EPSS 4.78% Exploit Prob.
Latest CVE CVE-2023-40623 Sep 12

Security Vulnerability Index

Page 3 / 6
4.0 CVSS

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids value in a GenerateCuids SOAPAction to the dswsbobje/services/biplatform URI.

EPSS: 0.41%
5.0 CVSS

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.

EPSS: 0.25%
10.0 CVSS
CVE-2010-0219
RCE Exploit Found

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

EPSS: 93.16%