CVE-2023-25617: OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-25617.
What is the severity level of CVE-2023-25617?
CVE-2023-25617 has a severity level of 8.8 (Critical).
Which versions of SAP Business Object are affected by CVE-2023-25617?
Versions 420 and 430 of SAP Business Object are affected by CVE-2023-25617.
What is the impact of CVE-2023-25617?
CVE-2023-25617 allows remote execution of arbitrary commands on Unix systems to authenticated users with scheduling rights.
How can I mitigate CVE-2023-25617?
To mitigate CVE-2023-25617, it is recommended to disable program objects execution for authenticated users with scheduling rights in SAP Business Object.