CVE-2023-37490: SAP Businessobjects Business Intelligence
Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system
Affected products
- SAP Businessobjects Business Intelligence: version 420 only; version 430 only
Published 2023-08-08. Last modified 2026-06-17.