First published: Tue Sep 14 2021(Updated: )
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP Business One vulnerability is CVE-2021-37532.
The severity of CVE-2021-37532 is medium with a severity value of 4.3.
SAP Business One version 10 is affected by CVE-2021-37532.
CVE-2021-37532 allows an authenticated user to gain access to a directory and view the contents of the index in the directory, which would otherwise be restricted to high privileged users.
To fix CVE-2021-37532, apply the necessary patches or updates provided by SAP Business One.