U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-26658

Change History

New CVE Received from SAP SE 3/10/2025 9:15:35 PM

Action Type Old Value New Value
Added Description

								
							
							
						
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/or write new data. To gain authenticated sessions of other users, the attacker must invest considerable time and effort. This vulnerability has a high impact on the confidentiality and integrity of the application with no effect on the availability of the application.
Added CVSS V3.1

								
							
							
						
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Added CWE

								
							
							
						
CWE-384
Added Reference

								
							
							
						
https://me.sap.com/notes/3561045
Added Reference

								
							
							
						
https://url.sap/sapsecuritypatchday