SAP Business One
cpe:2.3:a:sap:business_one:*:*:*:*:*:*:*
A vulnerability in the Service Layer of SAP Business One could allow attackers to gain unauthorized access, impersonate other users, and perform unauthorized actions within the application. This issue arises from improper session management, enabling attackers to escalate privileges and access, read, modify, or create data. Although exploiting this vulnerability requires significant time and effort to obtain authenticated sessions of other users, it poses a high risk to the application's confidentiality and integrity, with no impact on availability.
Successful exploitation could lead to unauthorized access and actions within the application, allowing attackers to impersonate other users, escalate privileges, and manipulate data.
Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day Bulletin. For guidance on accessing and applying SAP Security Notes, refer to the SAP Security Notes FAQs.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.