CVE-2023-7305: SmartBI RMIServlet Unrestricted File Upload RCE
SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7305?
CVE-2023-7305 is considered a critical vulnerability due to its potential for unrestricted file uploads and execution of arbitrary code.
How do I fix CVE-2023-7305?
To fix CVE-2023-7305, ensure that you apply the latest patches provided by SmartBI for versions V8, V9, and V10.
What are the affected versions for CVE-2023-7305?
CVE-2023-7305 affects SmartBI versions V8, V9, and V10.
What types of attacks are possible due to CVE-2023-7305?
Attackers can exploit CVE-2023-7305 to upload malicious files that could lead to sensitive operations or arbitrary code execution.
Is user interaction required to exploit CVE-2023-7305?
No, user interaction is not required to exploit CVE-2023-7305, making it more dangerous.