PT-2024-13244 · Comarch · Comarch Erp Xl

·

CVE-2023-4539

·

Published

2024-02-15

·

Updated

2024-02-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Comarch ERP XL versions 2020.2.2 through 2023.2
Description The issue is related to the use of a hard-coded password for a special database account created during Comarch ERP XL installation. This allows an attacker to retrieve embedded sensitive data stored in the database. The password is the same among all Comarch ERP XL installations.
Recommendations For Comarch ERP XL versions 2020.2.2 through 2023.2, consider changing the hard-coded password for the special database account to a unique and secure password to prevent unauthorized access to sensitive data. As a temporary workaround, restrict access to the database account until a secure password can be implemented.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4539

Affected Products

Comarch Erp Xl