PT-2023-15506 · Jedox · Jedox

Published

2023-05-02

·

Updated

2025-01-30

·

CVE-2022-47874

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jedox versions 2020.2.5
Description The issue allows remote authenticated users to view details of database connections via the class com.jedox.etl.mngr.Connections and the method getGlobalConnection() in the /tc/rpc endpoint.
Recommendations For version 2020.2.5, consider restricting access to the getGlobalConnection() method in the com.jedox.etl.mngr.Connections class to prevent unauthorized viewing of database connection details. As a temporary workaround, consider disabling the /tc/rpc endpoint until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-47874

Affected Products

Jedox