PT-2023-5923 · Sap · Sap Business One

Published

2023-10-10

·

Updated

2024-09-26

·

CVE-2023-41365

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Business One (B1i) version 10.0
Description The issue is related to the error reporting mechanism in SAP Business One, which allows an authorized attacker to retrieve the details of a fault message. This can be exploited to conduct an XXE injection, leading to information disclosure. Successful exploitation can cause limited impact on confidentiality, with no impact on integrity and availability. The vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations For SAP Business One (B1i) version 10.0, consider restricting access to error messages and stack traces to minimize the risk of exploitation. As a temporary workaround, consider disabling the error reporting feature until a patch is available.

Fix

XXE

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-06619
CVE-2023-41365

Affected Products

Sap Business One