Advisory
A note with CVSS 7.1 for component SBO-CRO-SEC was released by SAP on 08.08.2023. The correction/advisory 3337797 was described with "[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)" and affects the system type SAP Business One.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is sql injection within SAP Business One.
Risk specification
An authenticated attacker could leverage a vulnerability in SAP Business One to read or modify data via an SQL injection vulnerability.Solution
The application now properly checks the user-provided input.
- 9.9 [CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS
- 9.9 [CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
- 9.8 [CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner
- 9.1 [CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
- 8.8 [CVE-2021-42064] SQL Injection vulnerability in SAP Commerce