CVE-2023-25616: Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25616?
The severity of CVE-2023-25616 is critical with a rating of 8.8.
What is the affected software for CVE-2023-25616?
The affected software for CVE-2023-25616 is SAP Business Objects Business Intelligence Platform versions 420 and 430.
What is the vulnerability description of CVE-2023-25616?
CVE-2023-25616 is a code injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC) that allows an attacker to gain access to resources with extra privileges.
How can an attacker exploit CVE-2023-25616?
An attacker can exploit CVE-2023-25616 by executing a malicious program object in SAP Business Objects Business Intelligence Platform (CMC).
Are there any mitigations or fixes available for CVE-2023-25616?
To mitigate CVE-2023-25616, it is recommended to apply the necessary patches provided by SAP.