SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-45179 SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 25 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-09-25T15:28:05.273Z

Reserved: 2023-08-17T18:10:44.966Z

Link: CVE-2023-40623

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:51.035Z

cve-icon NVD

Status : Modified

Published: 2023-09-12T03:15:13.003

Modified: 2024-11-21T08:19:50.587

Link: CVE-2023-40623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.