Business one
This hub aggregates every CVE we track for Business one, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
3
Critical
13
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH13CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Business one.
- CVE-2026-24319Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)5.8
- CVE-2023-31403Improper Access Control vulnerability in SAP Business One product installation9.6
- CVE-2023-41365Information Disclosure vulnerability in SAP Business One (B1i)4.3
- CVE-2023-39437Cross-Site Scripting (XSS) vulnerability in SAP Business One7.6
- CVE-2023-37487Security misconfiguration vulnerability in SAP Business One (Service Layer)5.3
- CVE-2023-33993SQL Injection vulnerability in SAP Business One B1i Layer7.1
- CVE-2022-35292In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which al...7.8
- CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high p...7.5
- CVE-2022-35168Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.7.5
- CVE-2022-31593SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the applicat...8.8
- CVE-2021-44234SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.5.5
- CVE-2021-42066SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-dep...4.4
- CVE-2021-38180SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby exec...9.8
- CVE-2021-38179Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.4.9
- CVE-2021-33704The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover...8.8
Product normalization is registry-driven with AI assist and human review. How it works