HIGH🇬🇧 English

CVE-2023-33993

CVSS 7.1v3.1pub. 2023-08-08upd. 2024-11-21

B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and availability of the application.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
  • Sap Business One

    APP
    Sap
    10.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLi
CWE
Referencje

Powiązane podatności

CVE-2023-31403CRITICAL9.6PL ✓ten sam produkt

SAP Business One: brak uwierzytelnienia do folderu SMB podczas instalacji

CVE-2021-38180CRITICAL9.8PL ✓ten sam produkt

SAP Business One – CSV Injection przy eksporcie danych do Excel

CVE-2016-6256CRITICAL9.6PL ✓ten sam produkt

XXE w SAP Business One dla Android 1.2.3 — atak przez spreparowane dane XML

CVE-2023-39437HIGH7.6ten sam produkt

SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web ...

CVE-2022-35292HIGH7.8ten sam produkt

In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclo...