CVE-2009-4988 is a critical stack-based buffer overflow vulnerability in SAP Business One 2005 A, affecting versions 6.80.123 and 6.80.320. This flaw allows unauthenticated remote attackers to execute arbitrary code by sending a crafted GIOP request to TCP port 30000. With a CVSS score of 10.0, it represents a complete compromise of confidentiality, integrity, and availability, requiring no user interaction or authentication. While not currently on the KEV catalog, public exploit code, including Metasploit modules and ExploitDB entries, is readily available, indicating a high potential for exploitation. Despite its age and severity, there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.80.123CPE matchmatch criteria | cpe:2.3:a:sap:business_one_2005-a:6.80.123:*:*:*:*:*:*:* | ||
6.80.320CPE matchmatch criteria | cpe:2.3:a:sap:business_one_2005-a:6.80.320:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.