OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9epss 0.9%
exploitation probability
0.9%top 41% of all CVEs
observed exploitation
nono source reports it
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
SAP · Business Objects (Adaptive Job Server)