First published: Tue Mar 14 2023(Updated: )
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =420 | |
SAP Business Objects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-25616 is critical with a rating of 8.8.
The affected software for CVE-2023-25616 is SAP Business Objects Business Intelligence Platform versions 420 and 430.
CVE-2023-25616 is a code injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC) that allows an attacker to gain access to resources with extra privileges.
An attacker can exploit CVE-2023-25616 by executing a malicious program object in SAP Business Objects Business Intelligence Platform (CMC).
To mitigate CVE-2023-25616, it is recommended to apply the necessary patches provided by SAP.