CVE-2023-31403

Published Nov 14, 2023

Last updated 2 months ago

Overview

Description
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
Source
cna@sap.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cna@sap.com
CWE-863
nvd@nist.gov
CWE-863

Social media

Hype score
Not currently trending

Configurations