PT-2022-4736 · Sap · Sap Businessobjects Bw Publisher Service
Published
2022-05-24
·
Updated
2022-07-16
·
CVE-2022-31591
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP BusinessObjects BW Publisher Service versions 420, 430
Description
The issue is related to the absence of quotes in writing elements or search paths, which can be exploited by a local attacker to gain elevated privileges by inserting an executable file in the path of the affected service.
Recommendations
For versions 420 and 430, consider restricting access to the search path to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using unquoted elements in the search path to reduce the vulnerability to privilege escalation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Businessobjects Bw Publisher Service