Database Exposure Vulnerability in SAP Business One
CVE-2021-42066

4.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 December 2021

Summary

The vulnerability exists in SAP Business One version 10.0, where an admin user can access database passwords in plain text while transmitted over the network, violating data protection principles. Although exploiting this flaw requires deep knowledge of the application, successful exploitation could lead to significant risks, including a total compromise of the application's confidentiality, integrity, and availability. Organizations using this software must ensure they apply necessary patches and take proactive measures to secure their database connections.

Affected Version(s)

SAP Business One < 10.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.