Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap business one 10.0 vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv3
CVE-2021-44234
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Sap Business One 10.0
4.4
CVSSv3
CVE-2021-42066
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an malicious user to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be ...
Sap Business One 10.0
4.9
CVSSv3
CVE-2021-38179
Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
Sap Business One 10.0
9.8
CVSSv3
CVE-2021-38180
SAP Business One - version 10.0, allows an malicious user to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim a...
Sap Business One 10.0
7.8
CVSSv3
CVE-2021-33700
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take ...
Sap Business One 10.0
8.8
CVSSv3
CVE-2021-33704
The Service Layer of SAP Business One, version - 10.0, allows an authenticated malicious user to invoke certain functions that would otherwise be restricted to specific users. For an malicious user to discover the vulnerable function, no in-depth system knowledge is required. Onc...
Sap Business One 10.0
8.8
CVSSv3
CVE-2021-33698
SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation.
Sap Business One 10.0
4.3
CVSSv3
CVE-2021-37532
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
Sap Business One 10.0
4.3
CVSSv3
CVE-2021-33688
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
Sap Business One 10.0
6.5
CVSSv3
CVE-2021-33685
SAP Business One version - 10.0 allows low-level authorized malicious user to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high level sensitive data
Sap Business One 10.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »