When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.
History

Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.
Title Insecure Storage of Sensitive Information in SAP Business One (SLD)
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-09-09T02:11:26.232Z

Reserved: 2025-04-16T13:25:34.581Z

Link: CVE-2025-42933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-09T02:15:41.787

Modified: 2025-09-09T02:15:41.787

Link: CVE-2025-42933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.