SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3049661 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 May 2021, 16:11
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://launchpad.support.sap.com/#/notes/3049661 - Permissions Required, Vendor Advisory | |
References | (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655 - Vendor Advisory | |
CWE | CWE-74 | |
CVSS |
v2 : v3 : |
v2 : 3.6
v3 : 7.1 |
CPE | cpe:2.3:a:sap:business_one:8.82:*:*:*:*:*:*:* cpe:2.3:a:sap:business_one:9.3:*:*:*:*:*:*:* cpe:2.3:a:sap:business_one:9.0:*:*:*:*:*:*:* cpe:2.3:a:sap:business_one:9.1:*:*:*:*:*:*:* cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:* cpe:2.3:a:sap:business-one-hana-chef-cookbook:0.1.6:*:*:*:*:*:*:* cpe:2.3:a:sap:business-one-hana-chef-cookbook:0.1.7:*:*:*:*:*:*:* cpe:2.3:a:sap:business-one-hana-chef-cookbook:0.1.19:*:*:*:*:*:*:* cpe:2.3:a:sap:business_one:9.2:*:*:*:*:*:*:* |
Information
Published : 2021-05-11 15:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-27614
Mitre link : CVE-2021-27614
CVE.ORG link : CVE-2021-27614
JSON object : View
Products Affected
sap
- business_one
- business-one-hana-chef-cookbook
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')