CVE-2023-7305: SmartBI RMIServlet Unrestricted File Upload RCE

Published Oct 15, 2025
·
Updated

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.

Affected Software

1 affected component
SmartBI SmartBI>=8<10

Event History

Oct 15, 2025
CVE Published
via MITRE·01:24 AM
Data Sourced
via MITRE·01:24 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-7305?

CVE-2023-7305 is considered a critical vulnerability due to its potential for unrestricted file uploads and execution of arbitrary code.

2

How do I fix CVE-2023-7305?

To fix CVE-2023-7305, ensure that you apply the latest patches provided by SmartBI for versions V8, V9, and V10.

3

What are the affected versions for CVE-2023-7305?

CVE-2023-7305 affects SmartBI versions V8, V9, and V10.

4

What types of attacks are possible due to CVE-2023-7305?

Attackers can exploit CVE-2023-7305 to upload malicious files that could lead to sensitive operations or arbitrary code execution.

5

Is user interaction required to exploit CVE-2023-7305?

No, user interaction is not required to exploit CVE-2023-7305, making it more dangerous.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203