First published: Tue Mar 14 2023(Updated: )
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Business Objects Business Intelligence Platform | =420 | |
SAP Business Objects Business Intelligence Platform | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-25617.
CVE-2023-25617 has a severity level of 8.8 (Critical).
Versions 420 and 430 of SAP Business Object are affected by CVE-2023-25617.
CVE-2023-25617 allows remote execution of arbitrary commands on Unix systems to authenticated users with scheduling rights.
To mitigate CVE-2023-25617, it is recommended to disable program objects execution for authenticated users with scheduling rights in SAP Business Object.