Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap business one 10.0 vulnerabilities and exploits
(subscribe to this query)
187
VMScore
CVE-2021-44234
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Sap Business One 10.0
312
VMScore
CVE-2021-42066
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an malicious user to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be ...
Sap Business One 10.0
356
VMScore
CVE-2021-38179
Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
Sap Business One 10.0
828
VMScore
CVE-2021-38180
SAP Business One - version 10.0, allows an malicious user to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim a...
Sap Business One 10.0
580
VMScore
CVE-2021-33698
SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation.
Sap Business One 10.0
578
VMScore
CVE-2021-33704
The Service Layer of SAP Business One, version - 10.0, allows an authenticated malicious user to invoke certain functions that would otherwise be restricted to specific users. For an malicious user to discover the vulnerable function, no in-depth system knowledge is required. Onc...
Sap Business One 10.0
409
VMScore
CVE-2021-33700
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take ...
Sap Business One 10.0
356
VMScore
CVE-2021-33688
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
Sap Business One 10.0
356
VMScore
CVE-2021-33685
SAP Business One version - 10.0 allows low-level authorized malicious user to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high level sensitive data
Sap Business One 10.0
445
VMScore
CVE-2021-33686
Under certain conditions, SAP Business One version - 10.0, allows an unauthorized malicious user to get access to some encrypted sensitive information, but does not have control over kind or degree.
Sap Business One 10.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »