CVE Database
/

CVE-2026-24319

Back to search

CVE-2026-24319

Published: Feb 10, 2026

Modified: Feb 26, 2026

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.

VendorProductVersions

SAP_SE

SAP Business One (B1 Client Memory Dump Files)

affected
B1_ON_HANA 10.0
affected
SAP-M-BO 10.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now