Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3561045
was released on
11.03.2025 and deals with
"[CVE-2025-26658] Broken Authentication in SAP Business One (Service Layer)" within SAP Business One.
We advice you to follow the instructions, to resolve
weak security function / cryptographic algorithm
with a
medium potential for exploitation
in component SBO-CRO-SEC.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
The Service Layer in SAP Business One allows an unauthenticated attacker to impersonate other users due to insecure session UUID generation, resulting in the escalation of privileges and high impact on the confidentiality of the application.Solution
SAP Business One now uses a secure method of session identifier generation.