CVE-2022-28771: High severity SAP Business one License service API vulnerability
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28771?
CVE-2022-28771 is considered a critical vulnerability due to its potential to allow unauthenticated attackers to disrupt the application.
How do I fix CVE-2022-28771?
To fix CVE-2022-28771, ensure that proper authentication checks are implemented for the SAP Business One License service API.
What versions are affected by CVE-2022-28771?
CVE-2022-28771 specifically affects SAP Business One License service API version 10.0.
What can an attacker do with CVE-2022-28771?
An attacker exploiting CVE-2022-28771 can send malicious HTTP requests, potentially making the application inaccessible.
Is there a workaround for CVE-2022-28771?
While there is no official workaround for CVE-2022-28771, improving network security measures can help in mitigating the risk until a patch is applied.