Advisory
A note with CVSS 5.3 for component SBO-INT-B1IF was released by SAP on 10.06.2025. The correction/advisory 3594258 was described with "[CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework" and affects the system type SAP Business One.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is insufficient security function within SAP Business One.
Risk specification
SAP Business One Integration Framework contains a vulnerability that allows an unauthenticated attacker to bypass HTTP 403 Forbidden restrictions by manipulating the Host header in HTTP requests. This could lead to unauthorized access to otherwise restricted pages.Solution
The application has been updated to disregard client-supplied HTTP headers, thereby preventing header-based bypass techniques and strengthening access control to restricted resources.
- 9.0 [CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- 8.5 [CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation
- 6.7 [CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
- 6.5 Information Disclosure vulnerability in SAP Business Client
- 6.3 [CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1