CVE-2023-24530: Malicious File Upload
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24530?
CVE-2023-24530 is a vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC) versions 420 and 430 that allows an authenticated admin user to upload malicious code that can be executed by the application over the network.
What is the severity of CVE-2023-24530?
CVE-2023-24530 has a severity level of critical, with a CVSS score of 9.1.
How can an attacker exploit CVE-2023-24530?
An attacker can exploit CVE-2023-24530 by uploading malicious code as an authenticated admin user, which can be executed by the application over the network.
How can I fix CVE-2023-24530?
To fix CVE-2023-24530, it is recommended to apply the necessary security patches or updates provided by SAP.
Are there any additional resources for CVE-2023-24530?
Yes, you can find additional resources for CVE-2023-24530 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/3256787) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).