CVE-2021-27613: High severity sap business one vulnerability
Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure and highly impact system confidentiality, integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27613?
CVE-2021-27613 is classified as a high-severity vulnerability due to its potential to expose sensitive payroll information.
How do I fix CVE-2021-27613?
To fix CVE-2021-27613, ensure that the SAP Business One Chef cookbook is updated to the latest version that addresses the insecure temporary folder vulnerability.
Which versions of SAP Business One are affected by CVE-2021-27613?
CVE-2021-27613 affects SAP Business One versions 9.2, 9.3, and 10.0 using the specified Chef cookbook.
What type of attacks can CVE-2021-27613 facilitate?
CVE-2021-27613 can enable attackers to access sensitive payroll data by exploiting an insecure temporary folder.
Is there a workaround for CVE-2021-27613?
While a patch is recommended, administrative measures to restrict access to the temporary folder can serve as a temporary workaround for CVE-2021-27613.