Business Client
by SAP
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31593 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2022 | SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | ||
| CVE-2020-6244 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2020 | SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control… | ||
| CVE-2020-6228 | Hig | 0.49 | 7.5 | 0.00 | Apr 14, 2020 | SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer. | ||
| CVE-2018-2398 | Hig | 0.49 | 7.5 | 0.01 | Mar 14, 2018 | Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted. | ||
| CVE-2021-38150 | Med | 0.42 | 6.5 | 0.01 | Sep 14, 2021 | When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker… |
- risk 0.57cvss 8.8epss 0.01
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- risk 0.51cvss 7.8epss 0.00
SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control…
- risk 0.49cvss 7.5epss 0.00
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer.
- risk 0.49cvss 7.5epss 0.01
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
- risk 0.42cvss 6.5epss 0.01
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker…