Sensitive Information Exposure in SAP Business One and HANA Cockpit
CVE-2022-32249
7.5HIGH
Summary
In specific integration scenarios between SAP Business One and SAP HANA version 10.0, attackers can exploit vulnerabilities in the HANA cockpit's data volume. This exploitation can lead to unauthorized access to highly sensitive information, such as privileged account credentials, posing significant security risks to organizations.
Affected Version(s)
SAP Business one 10.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved