When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.
History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap business One
Vendors & Products Sap
Sap business One

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.
Title Insecure Storage of Sensitive Information in SAP Business One (SLD)
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-09-09T02:11:26.232Z

Updated: 2025-09-10T03:56:03.771Z

Reserved: 2025-04-16T13:25:34.581Z

Link: CVE-2025-42933

cve-icon Vulnrichment

Updated: 2025-09-09T13:31:10.284Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T02:15:41.787

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-42933

cve-icon Redhat

No data.