PT-2021-6148 · Sap · Sap Business One

Published

2021-08-13

·

Updated

2021-09-28

·

CVE-2021-33698

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Business One version 10.0
Description The issue is related to a lack of restrictions on file uploads in the system, allowing a remote attacker to upload and execute arbitrary files. This can be done by an attacker with business authorization, who can upload any files, including script files, without proper file format validation.
Recommendations For SAP Business One version 10.0, consider restricting file upload capabilities to authorized personnel and validating file formats before allowing uploads to prevent exploitation. As a temporary workaround, consider disabling file upload functionality until a patch is available.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01024
CVE-2021-33698

Affected Products

Sap Business One