First published: Wed Sep 15 2021(Updated: )
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take substantial control of the vulnerable application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33700.
The severity of CVE-2021-33700 is high (7.8).
SAP Business One version 10.0 is affected by CVE-2021-33700.
A local attacker with access to the victim's browser can exploit CVE-2021-33700 to login as the victim without knowing their password.
If an attacker successfully exploits CVE-2021-33700, they can obtain highly sensitive information and take substantial control of the victim's account.