Advisory
On 09.09.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Business One.
SAP Note 3642961 addresses "[CVE-2025-42933] Insecure Storage of Sensitive Information in SAP Business One (SLD)" to prevent insecure storage of sensitive data (password) with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAP Business One SLD backend service transmits credentials in cleartext HTTP responses, enabling authenticated attackers to intercept them and gain unauthorized system access.Solution
SAP Business One SLD backend service now encrypts database passwords within HTTP responses, preventing credential exposure.