First published: Wed Jun 10 2020(Updated: )
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =9.3 | |
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-6239.
The severity of CVE-2020-6239 is medium (4.4).
SAP Business One versions 9.3 and 10.0 are affected by CVE-2020-6239.
CVE-2020-6239 allows an attacker with admin permissions to view the SYSTEM user password in clear text, leading to information disclosure.
To fix CVE-2020-6239, update SAP Business One to a patched version as recommended by SAP.