PT-2023-4240 · Sap · Sap Business Objects Installer
Published
2023-08-08
·
Updated
2023-08-09
·
CVE-2023-37490
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business Objects Installer versions 420, 430
Description
The issue is related to an uncontrolled search path element in the SAP BusinessObjects Business Intelligence platform installer. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information by substituting an executable file. An authenticated attacker within the network can overwrite an executable file created in a temporary directory during the installation process, potentially compromising the system.
Recommendations
For versions 420 and 430, consider restricting access to the temporary directory used during the installation process to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using the installer on untrusted networks to reduce the risk of an authenticated attacker overwriting executable files.
Restrict network access to the installer to only trusted users to prevent potential exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business Objects Installer