CVE-2025-42933
8.8SAP · Business One (SLD)
The SAP Business One SLD backend service fails to enforce proper encryption on certain APIs, leading to the exposure of sensitive credentials within the HTTP response body.
Executive summary
A vulnerability in the SAP Business One SLD service allows authenticated attackers to capture sensitive credentials due to insufficient API encryption.
Vulnerability
This is an instance of Insufficiently Protected Credentials (CWE-522) where the SLD backend service fails to encrypt sensitive data returned in HTTP responses. The vulnerability requires the attacker to be an authenticated user to trigger the affected API calls.
Business impact
The exposure of credentials in cleartext poses a severe risk to the confidentiality, integrity, and availability of the entire SAP Business One environment. With a CVSS score of 8.8, this vulnerability is categorized as High, as it provides a trivial path for an attacker to escalate privileges or gain unauthorized access to core business data and administrative functions.
Remediation
Immediate Action: Review the official SAP security note 3642961 and apply the corresponding security updates or configuration changes provided by the vendor.
Proactive Monitoring: Monitor network traffic and application logs for unusual patterns or access to the SLD backend service that deviate from established baselines.
Compensating Controls: Implement network-level encryption or ensure that communication between the native client and the SLD service is restricted to trusted segments to minimize the risk of interception.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the critical nature of credential exposure within enterprise resource planning software, this vulnerability represents a significant security risk. Administrators should prioritize the application of vendor-provided patches or configuration hardening immediately to prevent unauthorized access and potential lateral movement within the network.