Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9983-52gj-4grg

Опубликовано: 10 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.

SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.

EPSS

Процентиль: 31%
0.00115
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-209
CWE-611

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость системы управления ресурсами предприятия SAP Business One, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и реализовать XXE-атаки

EPSS

Процентиль: 31%
0.00115
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-209
CWE-611