Vulnerability Description
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business One | 10.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3069882Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3069882Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
FAQ
What is CVE-2021-33688?
CVE-2021-33688 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
How severe is CVE-2021-33688?
CVE-2021-33688 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33688?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business One.