PT-2023-15506 · Jedox · Jedox

CVE-2022-47874

·

Publicado

2023-05-02

·

Atualizado

2025-01-30

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jedox versions 2020.2.5
Description The issue allows remote authenticated users to view details of database connections via the class com.jedox.etl.mngr.Connections and the method getGlobalConnection() in the /tc/rpc endpoint.
Recommendations For version 2020.2.5, consider restricting access to the getGlobalConnection() method in the com.jedox.etl.mngr.Connections class to prevent unauthorized viewing of database connection details. As a temporary workaround, consider disabling the /tc/rpc endpoint until a patch is available.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47874

Produtos afetados

Jedox