Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gw6j-cw44-6794

Опубликовано: 10 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

EPSS

Процентиль: 4%
0.00019
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 5.3
nvd
8 месяцев назад

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

CVSS3: 5.3
fstec
8 месяцев назад

Уязвимость системы управления ресурсами предприятия SAP Business One, связанная с недостатком в механизме подтверждения источника, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 4%
0.00019
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-346