SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HSap Business One
APPSap10.0
Related vulnerabilities
SAP Business One – CSV Injection przy eksporcie danych do Excel
XXE w SAP Business One dla Android 1.2.3 — atak przez spreparowane dane XML
B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to...
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web ...
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclo...