CVE-2020-6239

MEDIUM

SAP Business One <10.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2908382

Scores

CVSS v3 4.4
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (2)
sap/business_one 9.3
sap/business_one 10.0
Published Jun 10, 2020
Tracked Since Feb 18, 2026