First published: Tue Feb 14 2023(Updated: )
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Businessobjects Business Intelligence Platform | =420 | |
Sap Businessobjects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24530 is a vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC) versions 420 and 430 that allows an authenticated admin user to upload malicious code that can be executed by the application over the network.
CVE-2023-24530 has a severity level of critical, with a CVSS score of 9.1.
An attacker can exploit CVE-2023-24530 by uploading malicious code as an authenticated admin user, which can be executed by the application over the network.
To fix CVE-2023-24530, it is recommended to apply the necessary security patches or updates provided by SAP.
Yes, you can find additional resources for CVE-2023-24530 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/3256787) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).