PT-2025-36560 · Sap · Sap Business One

Published

2025-09-09

·

Updated

2025-09-14

·

CVE-2025-42933

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SAP Business One (affected versions not specified)
Description: A flaw exists in the SLD backend service of SAP Business One when a user logs in via the native client. The service fails to enforce proper encryption of certain APIs, leading to the exposure of sensitive credentials within the HTTP response body. This impacts the confidentiality, integrity, and availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-12402
CVE-2025-42933

Affected Products

Sap Business One