Description
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

Published: 2023-09-12
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-45179 SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.
History

Wed, 25 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Sap Businessobjects
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-09-25T15:28:05.273Z

Reserved: 2023-08-17T18:10:44.966Z

Link: CVE-2023-40623

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:51.035Z

cve-icon NVD

Status : Modified

Published: 2023-09-12T03:15:13.003

Modified: 2024-11-21T08:19:50.587

Link: CVE-2023-40623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses