VulnerabilityModified
CVE-2018-2425
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted.
MEDIUM 5.5EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- sap/business one
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/104438Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2588475Issue Tracking, Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255Vendor Advisory
- http://www.securityfocus.com/bid/104438Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2588475Issue Tracking, Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.