CVE-2021-37532: Path Traversal
Published Sep 14, 2021
·Updated
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
Affected Software
1 affected component
SAP Business One=10.0
Event History
Sep 14, 2021
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SAP Business One vulnerability?
The vulnerability ID for this SAP Business One vulnerability is CVE-2021-37532.
2
What is the severity of CVE-2021-37532?
The severity of CVE-2021-37532 is medium with a severity value of 4.3.
3
What is affected by CVE-2021-37532?
SAP Business One version 10 is affected by CVE-2021-37532.
4
How does CVE-2021-37532 allow an attacker to gain unauthorized access?
CVE-2021-37532 allows an authenticated user to gain access to a directory and view the contents of the index in the directory, which would otherwise be restricted to high privileged users.
5
How can I fix CVE-2021-37532?
To fix CVE-2021-37532, apply the necessary patches or updates provided by SAP Business One.