CVE-2021-38179

Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-522 NVD-CWE-Other

19 Oct 2021, 00:49

Type Values Removed Values Added
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.9
References (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983 - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3074819 - (MISC) https://launchpad.support.sap.com/#/notes/3074819 - Permissions Required
CPE cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*

12 Oct 2021, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-12 15:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-38179

Mitre link : CVE-2021-38179

CVE.ORG link : CVE-2021-38179


JSON object : View

Products Affected

sap

  • business_one