Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-40623

Опубликовано: 12 сент. 2023
Источник: nvd
CVSS3: 6.2
CVSS3: 7.1
EPSS Низкий

Описание

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:businessobjects:420:*:*:*:-:*:*:*
cpe:2.3:a:sap:businessobjects:430:*:*:*:-:*:*:*

EPSS

Процентиль: 36%
0.00153
Низкий

6.2 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-1386

Связанные уязвимости

CVSS3: 7.1
github
больше 2 лет назад

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

EPSS

Процентиль: 36%
0.00153
Низкий

6.2 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-1386