PT-2022-4736 · Sap · Sap Businessobjects Bw Publisher Service

Published

2022-05-24

·

Updated

2022-07-16

·

CVE-2022-31591

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP BusinessObjects BW Publisher Service versions 420, 430
Description The issue is related to the absence of quotes in writing elements or search paths, which can be exploited by a local attacker to gain elevated privileges by inserting an executable file in the path of the affected service.
Recommendations For versions 420 and 430, consider restricting access to the search path to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using unquoted elements in the search path to reduce the vulnerability to privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05631
CVE-2022-31591

Affected Products

Sap Businessobjects Bw Publisher Service