CVE-2018-2458

HIGH

SAP Business One <9.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.

References (3)

Core 3
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2670284
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105307

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
sap/business_one 9.2
sap/business_one 9.3
Published Sep 11, 2018
Tracked Since Feb 18, 2026