Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.