← Back

Business One

business_one

Vendor: Sap • 31 CVEs

CVEs (31)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Business One
Jun 17, 2026
Sep 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high leve...Show more
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high level sensitive dataShow less
1Sap
1Business One
Jun 17, 2026
Jun 9, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted.
1Sap
2Business One Hana Chef Cookbook
Business One
Jun 17, 2026
May 11, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and...Show more
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.Show less
1Sap
2Business One Hana Chef Cookbook
Business One
Jun 17, 2026
May 11, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could t...Show more
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.Show less
1Sap
1Business One
Jun 17, 2026
Jun 10, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.
1Sap
1Business One
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted.
1Sap
1Business One
Nov 21, 2024
Sep 11, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
1Sap
1Business One
Nov 21, 2024
Sep 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.
1Sap
1Business One
Nov 21, 2024
Jun 12, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted.
1Sap
1Business One
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
1Sap
1Business One
May 13, 2026
May 26, 2017
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/IN...Show more
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.Show less