First published: Tue Jul 12 2022(Updated: )
SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects BW Publisher Service | =420 | |
SAP BusinessObjects BW Publisher Service | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31591 is considered to have a high severity due to its potential to allow local attackers to elevate privileges.
To fix CVE-2022-31591, update SAP BusinessObjects BW Publisher Service to the latest version that addresses this vulnerability.
CVE-2022-31591 affects SAP BusinessObjects BW Publisher Service versions 420 and 430.
CVE-2022-31591 can be exploited by local attackers who have access to the system where the vulnerable service is running.
Systems running the impacted versions of SAP BusinessObjects BW Publisher Service, specifically versions 420 and 430, are vulnerable to CVE-2022-31591.