# CVE-2023-40623

## Summary

- **CVE ID:** CVE-2023-40623
- **Severity:** MEDIUM
- **CVSS Score:** 6.2 (CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H)
- **CWE:** CWE-1386
- **Published:** Sep 12, 2023
- **Last Modified:** Mar 13, 2026

## Description

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.

## Affected Products

- SAP_SE — SAP BusinessObjects Suite (Installer) (420)
- SAP_SE — SAP BusinessObjects Suite (Installer) (430)

## References

- [CNA](https://me.sap.com/notes/3317702)
- [CNA](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 36.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._