PT-2020-19035 · Sap · Sap Business One
Published
2020-06-10
·
Updated
2021-07-21
·
CVE-2020-6239
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Business One versions 9.3, 10.0
Description
The issue allows an attacker with admin permissions to view the SYSTEM user password in clear text under certain conditions, leading to information disclosure.
Recommendations
For versions 9.3 and 10.0, consider restricting access to the Backup service to minimize the risk of exploitation until a fix is available.
As a temporary workaround, limit admin permissions to only necessary personnel to reduce the potential for attackers to view sensitive information.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business One