HIGH · 7.6

CVE-2023-37490

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process...

Vulnerability Description

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system

CVSS Score

7.6

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SapBusinessobjects Business Intelligence420

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-37490?

CVE-2023-37490 is a vulnerability with a CVSS score of 7.6 (HIGH). SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process...

How severe is CVE-2023-37490?

CVE-2023-37490 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-37490?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Businessobjects Business Intelligence.