CVE-2023-25616
Published on: Not Yet Published
Last Modified on: 04/11/2023 10:15:00 PM UTC
Certain versions of Business Objects Business Intelligence Platform from Sap contain the following vulnerability:
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.
- CVE-2023-25616 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
SAP - Business Objects Business Intelligence Platform (CMC) version = 420
- Affected Vendor/Software:
SAP - Business Objects Business Intelligence Platform (CMC) version = 430
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
SAP Patch Day Blog | web.archive.org text/html Inactive LinkNot Archived |
![]() |
No Description Provided | launchpad.support.sap.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Sap | Business Objects Business Intelligence Platform | 420 | All | All | All |
Application | Sap | Business Objects Business Intelligence Platform | 430 | All | All | All |
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*:
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-25616 : In some scenario, #SAP Business Objects Business Intelligence Platform CMC - versions 420, 430,… twitter.com/i/web/status/1… | 2023-03-14 05:06:54 |
![]() |
CVE-2023-25616 | 2023-03-14 05:38:20 |
![]() |
CVE-2023-25616 | SAP Business Objects Business Intelligence Platform 420/430 CMC injection | 2023-04-07 06:05:49 |