PT-2020-19035 · Sap · Sap Business One

Published

2020-06-10

·

Updated

2021-07-21

·

CVE-2020-6239

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Business One versions 9.3, 10.0
Description The issue allows an attacker with admin permissions to view the SYSTEM user password in clear text under certain conditions, leading to information disclosure.
Recommendations For versions 9.3 and 10.0, consider restricting access to the Backup service to minimize the risk of exploitation until a fix is available. As a temporary workaround, limit admin permissions to only necessary personnel to reduce the potential for attackers to view sensitive information.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6239

Affected Products

Sap Business One