CVE-2023-39437: Cross-Site Scripting (XSS) vulnerability in SAP Business One
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity and Availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this SAP Business One vulnerability?
The vulnerability ID for this SAP Business One vulnerability is CVE-2023-39437.
What is the severity rating of CVE-2023-39437?
The severity rating of CVE-2023-39437 is high with a CVSS score of 5.4.
What does CVE-2023-39437 allow an attacker to do?
CVE-2023-39437 allows an attacker to insert malicious code into the content of a web page or application, resulting in cross-site scripting (XSS) attacks.
How does CVE-2023-39437 impact the Confidentiality, Integrity, and Availability of SAP Business One?
CVE-2023-39437 can result in harmful actions affecting the Confidentiality, Integrity, and Availability of SAP Business One.
Is there a patch or fix available for CVE-2023-39437?
Yes, SAP has released patches to address the vulnerability. Please refer to the SAP notes and documents provided in the references for more information.