CVE-2021-33700: High severity sap business one on hana vulnerability
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take substantial control of the vulnerable application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33700.
What is the severity of CVE-2021-33700?
The severity of CVE-2021-33700 is high (7.8).
Which version of SAP Business One is affected by CVE-2021-33700?
SAP Business One version 10.0 is affected by CVE-2021-33700.
How can a local attacker exploit CVE-2021-33700?
A local attacker with access to the victim's browser can exploit CVE-2021-33700 to login as the victim without knowing their password.
What can an attacker potentially do if they exploit CVE-2021-33700?
If an attacker successfully exploits CVE-2021-33700, they can obtain highly sensitive information and take substantial control of the victim's account.