VYPR
High severity8.8NVD Advisory· Published Sep 15, 2021· Updated Jun 17, 2026

CVE-2021-33704

CVE-2021-33704

Description

The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited via Network stack, the attacker may be able to read, modify or delete restricted data. The impact is that missing authorization can result of abuse of functionality usually restricted to specific users.

Affected products

3
  • cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*
    • (no CPE)range: 10.0
  • SAP SE/SAP Business Onev5
    Range: < 10.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.