SAP Business One (B1i) - version 10.0, allows an...
Moderate severity
Unreviewed
Published
Oct 10, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Description
Published by the National Vulnerability Database
Oct 10, 2023
Published to the GitHub Advisory Database
Oct 10, 2023
Last updated
Sep 26, 2024
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.
References