<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:17:42 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0228 — De multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0228</link>
      <description>certfr-2023-avi-0228</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0228</guid>
    </item>
    <item>
      <title>cnvd-2023-100015</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-100015</link>
      <description>cnvd-2023-100015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-100015</guid>
    </item>
    <item>
      <title>EUVD-2026-219476</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-219476</link>
      <description>EUVD-2026-219476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-219476</guid>
    </item>
    <item>
      <title>fkie_cve-2023-27894</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-27894</link>
      <description>&lt;p&gt;SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-27894</guid>
    </item>
    <item>
      <title>GHSA-w7jv-qf6x-vrwr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w7jv-qf6x-vrwr</link>
      <description>&lt;p&gt;SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w7jv-qf6x-vrwr</guid>
    </item>
    <item>
      <title>gsd-2023-27894</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-27894</link>
      <description>gsd-2023-27894</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-27894</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0635 — SAP Patchday März 2023</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0635</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0635</guid>
    </item>
  </channel>
</rss>
