First published: Tue Sep 14 2021(Updated: )
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high level sensitive data
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33685 is a vulnerability in SAP Business One version 10.0 that allows a low-level authorized attacker to traverse the file system and access files or directories outside the restricted directory.
CVE-2021-33685 allows a low-level authorized attacker to access high-level sensitive data in SAP Business One version 10.0.
CVE-2021-33685 has a severity rating of medium with a CVSS score of 6.5.
To fix CVE-2021-33685 in SAP Business One version 10.0, it is recommended to apply the latest security patches provided by SAP.
You can find more information about CVE-2021-33685 in the SAP support notes: [link](https://launchpad.support.sap.com/#/notes/3069032) and the SAP Wiki: [link](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405).