SAP November 2023 Security Patch Day includes three new and three updated security notes. The most severe “hot news” is an improper access control vulnerability, tracked as CVE-2023-31403 (CVSS score of 9.6), that impacts SAP Business One product installation.
“SAP Business One installation – version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.” reads the advisory. “As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.”
The second Hot News is an update to a Security Note released on September 2023 Patch Day, the issue tracked as CVE-2023-40309 (CVSS score 9.8) is a missing authorization check in SAP CommonCryptoLib