ZeroHour

CVE-2022-28771

CVSS 3.1
7.5 high
EPSS
<1%p60
Published
()
Modified
Description

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

Vendors
sap
Products
business one license service api
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.