First published: Tue Dec 14 2021(Updated: )
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able to completely compromise confidentiality, integrity, and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this SAP Business One vulnerability is CVE-2021-42066.
The severity level of CVE-2021-42066 is medium, with a severity value of 4.4.
The affected software for CVE-2021-42066 is SAP Business One version 10.0.
CVE-2021-42066 allows an attacker to view the DB password in plain text over the network, which should otherwise be encrypted.
To fix CVE-2021-42066, it is recommended to apply the necessary patches or updates provided by SAP Business One.