Advisory
A note with CVSS 7.1 for component SBO-CRO-SEC was released by SAP on 08.08.2023. The correction/advisory 3337797 was described with "[CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)" and affects the system type SAP Business One.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is sql injection within SAP Business One.
Risk specification
An authenticated attacker could leverage a vulnerability in SAP Business One to read or modify data via an SQL injection vulnerability.
Solution
The application now properly checks the user-provided input.
