← Back to browse · API

CVE-2023-0022

Severity
CRITICAL
CVSS
9.9
EPSS
0.00743
Risk score
39.86
CISA KEV
No
PoC
No
Published
2023-01-10
Modified
2025-04-09
First seen
2026-08-07
Aliases
EUVD-2023-12127, GHSA-W848-4388-CVV2
Products
SAP:BusinessObjects Business Intelligence platform (Analysis edition for OLAP) 420, SAP:BusinessObjects Business Intelligence platform (Analysis edition for OLAP) 430
Sources
euvd EUVD-2023-12127

Description

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.

References