Lucene search

K
cveSapCVE-2023-40623
HistorySep 12, 2023 - 3:15 a.m.

CVE-2023-40623

2023-09-1203:15:13
CWE-1386
sap
web.nvd.nist.gov
24
sap
businessobjects
suite
installer
cve-2023-40623
exploit
network
directory
link
operating system
integrity
availability

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

32.4%

SAP BusinessObjects SuiteΒ Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

Affected configurations

Nvd
Node
sapbusinessobjectsMatch420-
OR
sapbusinessobjectsMatch430-
VendorProductVersionCPE
sapbusinessobjects420cpe:2.3:a:sap:businessobjects:420:*:*:*:-:*:*:*
sapbusinessobjects430cpe:2.3:a:sap:businessobjects:430:*:*:*:-:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP BusinessObjects Suite (Installer)",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "420"
      },
      {
        "status": "affected",
        "version": "430"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

32.4%

Related for CVE-2023-40623