CVE-2020-6239: Medium severity sap business one on hana vulnerability
Published Jun 10, 2020
·Updated
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.
Affected Software
2 affected components
SAP Business One=9.3
SAP Business One=10.0
Event History
Jun 10, 2020
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-6239.
2
What is the severity of CVE-2020-6239?
The severity of CVE-2020-6239 is medium (4.4).
3
Which software versions are affected by CVE-2020-6239?
SAP Business One versions 9.3 and 10.0 are affected by CVE-2020-6239.
4
What is the impact of CVE-2020-6239?
CVE-2020-6239 allows an attacker with admin permissions to view the SYSTEM user password in clear text, leading to information disclosure.
5
How can I fix CVE-2020-6239?
To fix CVE-2020-6239, update SAP Business One to a patched version as recommended by SAP.