Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2021-27616

Disclosure Date: May 11, 2021 (last updated November 28, 2024)
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.
Attacker Value
Unknown

CVE-2021-27614

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.
Attacker Value
Unknown

CVE-2019-0353

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
Under certain conditions SAP Business One client (B1_ON_HANA, SAP-M-BO), before versions 9.2 and 9.3, allows an attacker to access information which would otherwise be restricted.
Attacker Value
Unknown

CVE-2018-2502

Disclosure Date: December 11, 2018 (last updated November 27, 2024)
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).
0
Attacker Value
Unknown

CVE-2018-2458

Disclosure Date: September 11, 2018 (last updated November 27, 2024)
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown

CVE-2018-2425

Disclosure Date: June 12, 2018 (last updated November 26, 2024)
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown

CVE-2018-2410

Disclosure Date: April 10, 2018 (last updated November 26, 2024)
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
0