sap business-one CVE-2021-33704 is a vulnerability in SAP Business One
Published on September 15, 2021

The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited via Network stack, the attacker may be able to read, modify or delete restricted data. The impact is that missing authorization can result of abuse of functionality usually restricted to specific users.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2021-33704 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2021-33704

Want to know whenever a new CVE is published for SAP Business One? stack.watch will email you.

 

Affected Versions

SAP SE SAP Business One Version < 10.0 is affected by CVE-2021-33704

Exploit Probability

EPSS
0.22%
Percentile
44.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.