Unquoted Service Path Vulnerability in SAP Business One Application
CVE-2022-35292
7.8HIGH
Summary
The vulnerability occurs in the SAP Business One application when creating a service. If the executable path includes spaces and is not enclosed in quotes, it results in an unquoted service path vulnerability. This can be exploited by adversaries to execute malicious payloads, granting them SYSTEM privileges. Consequently, this elevated access can severely impact the confidentiality, integrity, and availability of the system and its data.
Affected Version(s)
SAP Business One 10.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved