CVE-2022-31591

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
12/07/2022
Last modified:
16/07/2022

Description

SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:businessobjects_bw_publisher_service:420:*:*:*:*:*:*:*
cpe:2.3:a:sap:businessobjects_bw_publisher_service:430:*:*:*:*:*:*:*