Medium priority
SAP security note 3101299, "[CVE-2021-42066] Information Disclosure Vulnerability in SAP Business One", is a program error note released on 11.01.2022. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Business One allows an admin user to view the database password in plain text over the network, which should otherwise be encrypted. Although exploiting this vulnerability requires in-depth application knowledge, once leveraged, an attacker could completely compromise the confidentiality, integrity, and availability of the application.
- Access sensitive information such as database passwords.
- Compromise the application’s confidentiality, integrity, and availability.
Solution
Upgrade to SAP Business One FP2111 to address and mitigate this vulnerability. Ensure that all related files are enhanced as per the update.
CVSS
Score 6.6 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 3101299
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
