UNIX symbolic link following in SAP BusinessObjects Business Intelligence suite - CVE-2023-40623
Published: September 12, 2023
SAP BusinessObjects Business Intelligence suite
SAP
Description
The vulnerability allows a remote user to delete arbitrary files on the system.
The vulnerability exists due to a symlink following issue in SAP BusinessObjects Suite Installer. A remote user on the local network can create a folder in application's temporary directory and link it to a critical directory on the system. As a result, the application will remove the linked directory, which can lead to integrity and data availability issues.