Back to search
CVE-2021-42066
Published: Dec 14, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able to completely compromise confidentiality, integrity, and availability of the application.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP Business One | affected < 10.0 |
Weaknesses (CWE)
References
https://launchpad.support.sap.com/#/notes/3101299
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now