First published: Tue Aug 08 2023(Updated: )
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Business Intelligence | =420 | |
SAP BusinessObjects Business Intelligence | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37490 is a vulnerability in SAP Business Objects Installer versions 420 and 430, which allows an authenticated attacker within the network to overwrite an executable file created during the installation process and potentially compromise the system.
CVE-2023-37490 vulnerability has a severity level of critical, with a severity value of 9 out of 10.
The CVE-2023-37490 vulnerability affects SAP Business Objects Installer versions 420 and 430.
An authenticated attacker within the network can exploit the CVE-2023-37490 vulnerability by overwriting an executable file created during the installation process with a malicious file.
Yes, you can find more information about the CVE-2023-37490 vulnerability in the SAP security note: https://me.sap.com/notes/3317710 and the official documentation: https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html.