First published: Tue Jul 12 2022(Updated: )
Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit?s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-32249 is high.
An attacker can exploit CVE-2022-32249 by gaining access to highly sensitive information using HANA cockpit's data volume.
SAP Business One version 10.0 is affected by CVE-2022-32249.
Yes, a fix is available. Please refer to the SAP support documents provided for more information.
The CWE ID for CVE-2022-32249 is 668.