Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41365


SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.


Published

2023-10-10T02:15:10.777

Last Modified

2024-11-21T08:21:09.903

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap business_one 10.0 Yes

References