Business One
31 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Business One, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Business One CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High13
- Medium15
Latest CVEs
The 15 most recently published vulnerabilities affecting Business One.
- CVE-2026-24319Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)5.8
- CVE-2023-31403Improper Access Control vulnerability in SAP Business One product installation9.6
- CVE-2023-41365Information Disclosure vulnerability in SAP Business One (B1i)4.3
- CVE-2023-39437Cross-Site Scripting (XSS) vulnerability in SAP Business One7.6
- CVE-2023-37487Security misconfiguration vulnerability in SAP Business One (Service Layer)5.3
- CVE-2023-33993SQL Injection vulnerability in SAP Business One B1i Layer7.1
- CVE-2022-35292In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which al...7.8
- CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high p...7.5
- CVE-2022-35168Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.7.5
- CVE-2022-31593SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the applicat...8.8
- CVE-2021-44234SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.5.5
- CVE-2021-42066SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-dep...4.4
- CVE-2021-38180SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby exec...9.8
- CVE-2021-38179Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.4.9
- CVE-2021-33704The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover...8.8
Product grouping is registry-driven, with AI assist and human review. How it works