CVE-2022-35292
13.09.2022, 16:15
In SAP Business One application when a service is created, the executable path contains spaces and isnt enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries, it can be used to gain privileged permissions on a system or network leading to high impact on Confidentiality, Integrity, and Availability.Enginsight
Vendor | Product | Version |
---|---|---|
sap | business_one | 10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration