
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24319 is an information disclosure vulnerability in SAP Business One where sensitive information is written to the application's memory dump files without obfuscation or encryption. Affecting SAP Business One version 10.0 (including the SAP HANA variant), the flaw allows high-privileged local users to extract credentials and other sensitive data from these dump files, potentially enabling unauthorized operations within the B1 environment. It was published on February 10, 2026, with a patch released as part of SAP's February 2026 Security Patch Day. The vulnerability carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE, SAP Patch Day).
The root cause is classified under CWE-316 (Cleartext Storage of Sensitive Information in Memory) and CWE-312 (Cleartext Storage of Sensitive Information): SAP Business One writes sensitive data — such as credentials — to memory dump files without any obfuscation or encryption. Exploitation requires local access to the host system, high privileges, and user interaction (e.g., triggering a memory dump), making the attack vector local with low complexity once access is established. An attacker who can read these dump files can extract plaintext sensitive information directly. No public proof-of-concept or technical write-up detailing specific exploitation mechanics has been identified (Red Hat CVE, Onapsis Blog).
Successful exploitation results in high confidentiality and integrity impact, with no effect on availability. An attacker with local high-privilege access who obtains the memory dump files could extract sensitive credentials or configuration data, potentially enabling unauthorized modification of company data within the SAP Business One environment. Lateral movement within the B1 environment is a realistic risk if extracted credentials are reused for other SAP services or accounts (Red Hat CVE, SAP Patch Day).
SAP has released a patch for this vulnerability as part of the February 2026 Security Patch Day; administrators should apply the relevant SAP Security Note immediately via the SAP Support Portal. As interim mitigations, restrict local system access to SAP Business One 10.0 hosts to trusted administrators only, implement strict access controls on high-privilege accounts, and secure or restrict access to memory dump file directories. Additionally, consider implementing monitoring for unauthorized access to dump file locations and applying encryption controls for sensitive data at rest (SAP Patch Day, Onapsis Blog).
The vulnerability was covered as part of broader SAP February 2026 Patch Day roundups by security firms including Onapsis, SecurityBridge, and RedRays, which noted it among the lower-severity issues addressed that month. Coverage focused primarily on higher-severity vulnerabilities in SAP CRM and SAP S/4HANA patched in the same cycle, with CVE-2026-24319 receiving limited standalone attention due to its medium severity and high exploitation prerequisites (Onapsis Blog, SecurityBridge Blog, RedRays Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."