VulnerabilityModified
CVE-2021-38179
This allows Admin User to see the captured packet contents which may include User credentials.
MEDIUM 4.9EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- sap/business one
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/3074819Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3074819Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.