Unquoted Service Path Vulnerability in SAP Business One Application
CVE-2022-35292

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 September 2022

Summary

The vulnerability occurs in the SAP Business One application when creating a service. If the executable path includes spaces and is not enclosed in quotes, it results in an unquoted service path vulnerability. This can be exploited by adversaries to execute malicious payloads, granting them SYSTEM privileges. Consequently, this elevated access can severely impact the confidentiality, integrity, and availability of the system and its data.

Affected Version(s)

SAP Business One 10.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.