Arbitrary file upload in SAP Business One - CVE-2021-33698

 

Arbitrary file upload in SAP Business One - CVE-2021-33698

Published: August 10, 2021


Vulnerability identifier: #VU55669
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33698
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in SAP Business One. A remote authenticated user can upload a malicious file and execute it on the server.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

SAP Business One

How to mitigate CVE-2021-33698

Install updates from vendor's website.


External References

Related Security Bulletins