CVE-2020-6239: SAP Business One

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

Affected products

  • SAP Business One: version 9.3 only; version 10.0 only

Published 2020-06-10. Last modified 2026-06-17.