Business One (B1i)
by SAP
CVEs (36)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24319 | Med | 0.38 | 5.8 | 0.00 | Feb 10, 2026 | In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue… | ||
| CVE-2018-2460 | Med | 0.38 | 5.9 | 0.01 | Sep 11, 2018 | SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack. | ||
| CVE-2021-44234 | Med | 0.36 | 5.5 | 0.00 | Jan 14, 2022 | SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. | ||
| CVE-2019-0256 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2019 | Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted. | ||
| CVE-2021-33686 | Med | 0.35 | 5.3 | 0.01 | Sep 14, 2021 | Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree. | ||
| CVE-2018-2410 | Med | 0.35 | 5.4 | 0.01 | Apr 10, 2018 | SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability. | ||
| CVE-2025-42897 | Med | 0.34 | 5.3 | 0.00 | Nov 11, 2025 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the… | ||
| CVE-2023-37487 | Med | 0.34 | 5.3 | 0.01 | Aug 8, 2023 | SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the… | ||
| CVE-2021-38179 | Med | 0.32 | 4.9 | 0.01 | Oct 12, 2021 | Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials. | ||
| CVE-2021-42066 | Med | 0.29 | 4.4 | 0.00 | Dec 14, 2021 | SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able… | ||
| CVE-2021-33662 | Med | 0.29 | 4.4 | 0.00 | Jun 9, 2021 | Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted. | ||
| CVE-2020-6239 | Med | 0.29 | 4.4 | 0.00 | Jun 10, 2020 | Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure. | ||
| CVE-2023-41365 | Med | 0.28 | 4.3 | 0.00 | Oct 10, 2023 | SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the… | ||
| CVE-2021-37532 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2021 | SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User. | ||
| CVE-2021-33688 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2021 | SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained. | ||
| CVE-2009-4988 | 0.08 | — | 0.66 | Aug 25, 2010 | Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000. |
- risk 0.38cvss 5.8epss 0.00
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue…
- risk 0.38cvss 5.9epss 0.01
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
- risk 0.36cvss 5.5epss 0.00
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
- risk 0.36cvss 5.5epss 0.00
Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted.
- risk 0.35cvss 5.3epss 0.01
Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree.
- risk 0.35cvss 5.4epss 0.01
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
- risk 0.34cvss 5.3epss 0.00
Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the…
- risk 0.34cvss 5.3epss 0.01
SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the…
- risk 0.32cvss 4.9epss 0.01
Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.
- risk 0.29cvss 4.4epss 0.00
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledge is required, but once exploited the attacker may be able…
- risk 0.29cvss 4.4epss 0.00
Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted.
- risk 0.29cvss 4.4epss 0.00
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.
- risk 0.28cvss 4.3epss 0.00
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the…
- risk 0.28cvss 4.3epss 0.01
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.
- risk 0.28cvss 4.3epss 0.01
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
- CVE-2009-4988Aug 25, 2010risk 0.08cvss —epss 0.66
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.
Page 2 of 2