Critical severity9.6NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-31403
CVE-2023-31403
Description
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
Affected products
3cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*
- (no CPE)range: 10.0
- Range: 10.0
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- me.sap.com/notes/3355658nvdPermissions Required
News mentions
0No linked articles in our index yet.