CVE-2023-25617 is a critical remote command execution vulnerability affecting SAP BusinessObjects Business Intelligence Platform versions 420 and 430. Authenticated users with scheduling rights can execute arbitrary commands on Unix systems via BI Launchpad, Central Management Console, or custom applications if program object execution is enabled. With a CVSS score of 8.8 (High), this vulnerability allows attackers to compromise confidentiality, integrity, and availability. While there is no known public exploit code or active exploitation (not in KEV), it has garnered community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
420CPE matchmatch criteria | cpe:2.3:a:sap:business_objects_business_intelligence_platform:420:*:*:*:*:*:*:* | ||
430CPE matchmatch criteria | cpe:2.3:a:sap:business_objects_business_intelligence_platform:430:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.