Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
B1_ON_HANA 10.0
affected
SAP-M-BO 10.0
affected
Description
Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availability.
Problem types
CWE-522: Insufficiently Protected Credentials
Product status
B1_ON_HANA 10.0
SAP-M-BO 10.0