The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.
History

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
Description The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.
Title Security misconfiguration vulnerability in SAP Business One Integration Framework
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-06-10T00:14:11.037Z

Updated: 2025-06-10T15:14:57.460Z

Reserved: 2025-04-16T13:25:50.942Z

Link: CVE-2025-42998

cve-icon Vulnrichment

Updated: 2025-06-10T13:37:44.911Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T01:15:23.307

Modified: 2025-06-12T16:06:39.330

Link: CVE-2025-42998

cve-icon Redhat

No data.