Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

[CVE-2021-42066] Information Disclosure vulnerability in SAP Business One, SAP security note 3101299

SAP Note 3101299
Medium priority

SAP security note 3101299, "[CVE-2021-42066] Information Disclosure Vulnerability in SAP Business One", is a program error note released on 11.01.2022. Below are the symptom and SAP recommended solution.

ComponentSAP Business One > Cross Topics > Security in SAP Business One software
CategoryProgram error
PriorityMedium priority
StatusReleased for Customer
Released on11.01.2022

Description

Symptom

SAP Business One allows an admin user to view the database password in plain text over the network, which should otherwise be encrypted. Although exploiting this vulnerability requires in-depth application knowledge, once leveraged, an attacker could completely compromise the confidentiality, integrity, and availability of the application.

  • Access sensitive information such as database passwords.
  • Compromise the application’s confidentiality, integrity, and availability.

Solution

Upgrade to SAP Business One FP2111 to address and mitigate this vulnerability. Ensure that all related files are enhanced as per the update.

CVSS

Score 6.6 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 3101299

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More