VYPR

Business One (Service Layer)

by SAP

CVEs (1)

  • CVE-2018-2502MedDec 11, 2018
    risk 0.40cvss 6.1epss 0.01

    TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).