CVE-2021-33700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/09/2021
Last modified:
28/09/2021

Description

SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take substantial control of the vulnerable application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*