VYPR

Business One (B1i)

by SAP

CVEs (36)

  • CVE-2026-24319MedFeb 10, 2026
    risk 0.38cvss 5.8epss 0.00

    In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue…

  • CVE-2018-2460MedSep 11, 2018
    risk 0.38cvss 5.9epss 0.01

    SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.

  • CVE-2021-44234MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.00

    SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

  • CVE-2019-0256MedFeb 15, 2019
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted.

  • CVE-2021-33686MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree.

  • CVE-2018-2410MedApr 10, 2018
    risk 0.35cvss 5.4epss 0.01

    SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.

  • CVE-2025-42897MedNov 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the…

  • CVE-2023-37487MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the…

  • CVE-2021-38179MedOct 12, 2021
    risk 0.32cvss 4.9epss 0.01

    Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.

  • CVE-2021-42066MedDec 14, 2021
    risk 0.29cvss 4.4epss 0.00

    SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able…

  • CVE-2021-33662MedJun 9, 2021
    risk 0.29cvss 4.4epss 0.00

    Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted.

  • CVE-2020-6239MedJun 10, 2020
    risk 0.29cvss 4.4epss 0.00

    Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

  • CVE-2023-41365MedOct 10, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the…

  • CVE-2021-37532MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.

  • CVE-2021-33688MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.

  • CVE-2009-4988Aug 25, 2010
    risk 0.08cvss epss 0.66

    Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.

Page 2 of 2