First published: Tue Sep 12 2023(Updated: )
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =420 | |
SAP BusinessObjects | =430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40623 is a vulnerability in SAP BusinessObjects Suite Installer versions 420 and 430 that allows an attacker within the network to create a directory under the temporary directory and link it to a directory with operating system files, potentially leading to the deletion of all operating system files.
CVE-2023-40623 has a severity rating of 7.1 (high).
The affected software in CVE-2023-40623 is SAP BusinessObjects Suite Installer versions 420 and 430.
An attacker within the network can exploit CVE-2023-40623 by creating a directory under the temporary directory and linking it to a directory with operating system files.
To fix CVE-2023-40623, it is recommended to apply the necessary patches or updates provided by SAP BusinessObjects.