PT-2021-17548 · Sap · Sap Business One
Published
2021-05-11
·
Updated
2022-07-12
·
CVE-2021-27613
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business One Chef cookbook versions 9.2 through 10.0
Description
The issue allows an attacker to exploit an insecure temporary folder for incoming and outgoing payroll data, accessing restricted information. This could lead to information disclosure and significantly impact system confidentiality, integrity, and availability.
Recommendations
For versions 9.2 through 10.0, consider restricting access to the temporary folder used for payroll data to minimize the risk of exploitation. As a temporary workaround, limit the use of the insecure temporary folder until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Business One