Advisory
On 12.07.2022 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Business One .
SAP Note 3191012 addresses "[CVE-2022-31593] Code Injection vulnerability in SAP Business One" to prevent code injection with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP Business One client allows an attacker with low privileges to inject code that can be executed by the application, thereby controlling the application's behavior.
Solution
The attachments upload mechanism of the SAP Business One client has been enhanced with the ability to refuse uploading files of certain types, thus preventing dangerous files from spreading to other users or running in the system.
