Show filters
69 Total Results
Displaying 1-10 of 69
Sort by:
Attacker Value
High
CVE-2023-41179
Disclosure Date: September 19, 2023 (last updated October 08, 2023)
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.
Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
2
Attacker Value
Unknown
CVE-2020-8468
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
1
Attacker Value
Unknown
CVE-2023-31403
Disclosure Date: November 14, 2023 (last updated September 28, 2024)
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
0
Attacker Value
Unknown
CVE-2023-41365
Disclosure Date: October 10, 2023 (last updated September 26, 2024)
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.
0
Attacker Value
Unknown
CVE-2023-39437
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity and Availability of the application.
0
Attacker Value
Unknown
CVE-2023-37487
Disclosure Date: August 08, 2023 (last updated September 28, 2024)
SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the application
0
Attacker Value
Unknown
CVE-2023-33993
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2022-35292
Disclosure Date: September 13, 2022 (last updated October 08, 2023)
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries, it can be used to gain privileged permissions on a system or network leading to high impact on Confidentiality, Integrity, and Availability.
0
Attacker Value
Unknown
CVE-2022-36336
Disclosure Date: July 30, 2022 (last updated October 08, 2023)
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on detection patterns are not required to take any additional steps to mitigate this issue.
0
Attacker Value
Unknown
CVE-2022-35168
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.
0