Access Control Vulnerability in SAP Business One by SAP
CVE-2019-0353
3.3LOW
Summary
An access control vulnerability in SAP Business One client (B1_ON_HANA) allows unauthorized access to sensitive information in versions prior to 9.2 and 9.3. Attackers can exploit this flaw under specific conditions, potentially compromising sensitive data that should otherwise remain protected.
Affected Version(s)
SAP Business One Client < 9.2 < 9.2
SAP Business One Client < 9.3 < 9.3
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved