CVE-2025-42933: Insecure Storage of Sensitive Information in SAP Business One (SLD)
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42933?
CVE-2025-42933 is considered a high-severity vulnerability due to the risk of sensitive credentials being exposed.
How do I fix CVE-2025-42933?
To fix CVE-2025-42933, ensure that the latest security patches provided by SAP for Business One are applied.
What type of data is affected by CVE-2025-42933?
CVE-2025-42933 affects sensitive credentials that may be exposed in HTTP response bodies due to improper encryption.
Which software versions are vulnerable to CVE-2025-42933?
CVE-2025-42933 specifically affects SAP Business One native client implementations.
What are the potential consequences of CVE-2025-42933?
The consequences of CVE-2025-42933 include compromising the confidentiality and integrity of sensitive data.