First published: Tue Nov 14 2023(Updated: )
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31403.
The severity of CVE-2023-31403 is critical with a score of 9.6.
SAP Business One version 10.0 is affected by CVE-2023-31403.
CVE-2023-31403 allows malicious users to read, write, execute, or use files in SMB shared folders without proper authentication and authorization checks.
Yes, you can find more information about CVE-2023-31403 at the following references: [Reference 1](https://me.sap.com/notes/3355658) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).