CVE-2023-37487

Severity
5.3MEDIUM
EPSS
0.2%
top 58.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the application

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Security misconfiguration vulnerability in SAP Business One (Service Layer)2023-08-08
GHSA
GHSA-5f5v-chg4-g75r: SAP Business One (Service Layer) - version 102023-08-08
CVE-2023-37487 (MEDIUM CVSS 5.3) | SAP Business One (Service Layer) - | cvebase.io