Sap business one
This hub aggregates every CVE we track for Sap business one, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
30
CVEs tracked
2
Critical
13
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH13CRITICAL2
Monthly trend
0
0
0
0
0
0
1
0
0
1
0
1
1
0
1
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Sap business one.
- CVE-2025-42897Information Disclosure vulnerability in SAP Business One (SLD)5.3
- CVE-2025-42933Insecure Storage of Sensitive Information in SAP Business One (SLD)8.8
- CVE-2025-42951Broken Authorization in SAP Business One (SLD)8.8
- CVE-2025-42998Security misconfiguration vulnerability in SAP Business One Integration Framework5.3
- CVE-2025-26658Broken Authentication in SAP Business One (Service Layer)6.8
- CVE-2023-31403Improper Access Control vulnerability in SAP Business One product installation9.6
- CVE-2023-41365Information Disclosure vulnerability in SAP Business One (B1i)4.3
- CVE-2023-39437Cross-Site Scripting (XSS) vulnerability in SAP Business One7.6
- CVE-2023-37487Security misconfiguration vulnerability in SAP Business One (Service Layer)5.3
- CVE-2023-33993SQL Injection vulnerability in SAP Business One B1i Layer7.1
- CVE-2022-35292In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which al...7.8
- CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high p...7.5
- CVE-2022-35168Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.7.5
- CVE-2022-31593SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the applicat...8.8
- CVE-2021-44234SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.5.5
Product normalization is registry-driven with AI assist and human review. How it works