Vulnerability Description
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business One | 10.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3075546Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3075546Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405Vendor Advisory
FAQ
What is CVE-2021-37532?
CVE-2021-37532 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be rest...
How severe is CVE-2021-37532?
CVE-2021-37532 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37532?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business One.