CVE-2026-24319

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.
References
Link Resource
https://me.sap.com/notes/3679346 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_one:10.0:*:*:*:*:sap_hana:*:*

History

17 Feb 2026, 15:30

Type Values Removed Values Added
CWE CWE-312
First Time Sap business One
Sap
CPE cpe:2.3:a:sap:business_one:10.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_one:10.0:*:*:*:*:sap_hana:*:*
References () https://me.sap.com/notes/3679346 - () https://me.sap.com/notes/3679346 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
Summary
  • (es) En SAP Business One, la información sensible se escribe en los archivos de volcado de memoria de la aplicación sin ofuscación. Obtener acceso a esta información podría potencialmente conducir a operaciones no autorizadas dentro del entorno B1, incluyendo la modificación de datos de la empresa. Este problema resulta en un alto impacto en la confidencialidad y la integridad, sin impacto en la disponibilidad.

10 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 04:16

Updated : 2026-02-17 15:30


NVD link : CVE-2026-24319

Mitre link : CVE-2026-24319

CVE.ORG link : CVE-2026-24319


JSON object : View

Products Affected

sap

  • business_one
CWE
CWE-316

Cleartext Storage of Sensitive Information in Memory

CWE-312

Cleartext Storage of Sensitive Information