PT-2022-3937 · Sap · Sap Business One License Service Api
Published
2022-04-06
·
Updated
2023-08-14
·
CVE-2022-28771
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SAP Business One License service API version 10.0
Description
The issue is related to a missing authentication check in the SAP Business One License service API, allowing an unauthenticated attacker to send malicious HTTP requests over the network. Successful exploitation can enable an attacker to break the whole application, making it inaccessible. The vulnerability can be exploited by a remote attacker using a specially crafted HTTP request, potentially allowing the execution of arbitrary code.
Recommendations
For SAP Business One License service API version 10.0, consider implementing proper authentication checks to prevent unauthorized access. As a temporary workaround, restrict access to the API to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Business One License Service Api