CVE-2023-37490: Binary hijack in SAP BusinessObjects Business Intelligence (Installer)
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37490 vulnerability?
CVE-2023-37490 is a vulnerability in SAP Business Objects Installer versions 420 and 430, which allows an authenticated attacker within the network to overwrite an executable file created during the installation process and potentially compromise the system.
How severe is the CVE-2023-37490 vulnerability?
CVE-2023-37490 vulnerability has a severity level of critical, with a severity value of 9 out of 10.
What software versions are affected by the CVE-2023-37490 vulnerability?
The CVE-2023-37490 vulnerability affects SAP Business Objects Installer versions 420 and 430.
How can an attacker exploit the CVE-2023-37490 vulnerability?
An authenticated attacker within the network can exploit the CVE-2023-37490 vulnerability by overwriting an executable file created during the installation process with a malicious file.
Are there any references or resources related to the CVE-2023-37490 vulnerability?
Yes, you can find more information about the CVE-2023-37490 vulnerability in the SAP security note: https://me.sap.com/notes/3317710 and the official documentation: https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html.