Cyber Resilience

CVE-2023-40623

Sap Businessobjects 420 … 430

Published
12 September 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H
EPSS Score 0.0037 30th percentile
Risk Priority 44 floored blend · peak EPSS

Summary

CVE-2023-40623 is a medium-severity Insecure Operation on Windows Junction / Mount Point (CWE-1386) vulnerability in Sap Businessobjects. Its CVSS base score is 6.2 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Direct Volume Access (T1006); ranked at the 30th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the…

more

operating system files causing a limited impact on integrity and completely compromising the availability of the system.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1006 Direct Volume Access Stealth
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
T1548 Abuse Elevation Control Mechanism Privilege Escalation
Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions.
T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-28764Same product: Sap Businessobjects
CVE-2023-23698Shared CWE-1386
CVE-2024-36340Shared CWE-1386
CVE-2024-7400Shared CWE-1386
CVE-2025-58074Shared CWE-1386
CVE-2023-32470Shared CWE-1386
CVE-2025-31332Same vendor: Sap
CVE-2024-47595Same vendor: Sap
CVE-2025-42936Same vendor: Sap
CVE-2026-23684Same vendor: Sap

Affected Assets

sap
businessobjects
420, 430

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V5.3.3

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly prevent improper junction/mount-point handling during design and coding.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing can detect junction/mount-point weaknesses before release.

prevents

Secure development lifecycle can mandate junction/mount-point validation during design and coding.

prevents

Application security requirements can explicitly require protection against Windows reparse-point attacks.

prevents

Secure system architecture principles include canonicalization and path-traversal defenses that mitigate junction attacks.

prevents

Secure coding standards directly address safe file/directory handling to prevent insecure junction operations.

mitigates

Information access restriction reduces exposure but does not prevent the technical flaw itself.

References