← volver
CVE-2021-33704

CVE-2021-33704

CVSS 6.3 MEDIUMEPSS 0.6%CWE-862
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.3EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 sep 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited via Network stack, the attacker may be able to read, modify or delete restricted data. The impact is that missing authorization can result of abuse of functionality usually restricted to specific users.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
SAP SE · SAP Business One

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →