Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
References
| Link | Resource |
|---|---|
| https://launchpad.support.sap.com/#/notes/3074819 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 | Vendor Advisory |
| https://launchpad.support.sap.com/#/notes/3074819 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://launchpad.support.sap.com/#/notes/3074819 - Permissions Required | |
| References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - Vendor Advisory |
12 Jul 2022, 17:42
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-Other |
19 Oct 2021, 00:49
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 4.9 |
| CWE | CWE-522 | |
| CPE | cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:* | |
| References | (MISC) https://launchpad.support.sap.com/#/notes/3074819 - Permissions Required | |
| References | (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - Vendor Advisory |
12 Oct 2021, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2021-10-12 15:15
Updated : 2024-11-21 06:16
NVD link : CVE-2021-38179
Mitre link : CVE-2021-38179
CVE.ORG link : CVE-2021-38179
JSON object : View
Products Affected
sap
- business_one
CWE
