Critical severity9.9NVD Advisory· Published Mar 14, 2023· Updated Jun 17, 2026
CVE-2023-25616
CVE-2023-25616
Description
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.
Affected products
4cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:*
- cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:*
420, 430+ 1 more
- (no CPE)range: 420, 430
- (no CPE)range: 420
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.