CVE-2023-24530: SAP Businessobjects Business Intelligence Platform

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.

Affected products

  • SAP Businessobjects Business Intelligence Platform: version 420 only; version 430 only

Published 2023-02-14. Last modified 2026-06-17.