PT-2022-12024 · Sap · Sap Business One
Published
2022-01-14
·
Updated
2022-01-21
·
CVE-2021-44234
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Business One version 10.0
Description
The issue concerns the extended log in SAP Business One, which stores sensitive information. This can provide valuable guidance to an attacker or expose sensitive user information.
Recommendations
For SAP Business One version 10.0, consider restricting access to the extended log to minimize the risk of sensitive information exposure.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business One