PT-2024-13244 · Comarch · Comarch Erp Xl
Marcin Ochab
·
Published
2024-02-15
·
Updated
2024-02-17
·
CVE-2023-4539
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Comarch ERP XL versions 2020.2.2 through 2023.2
Description
The issue is related to the use of a hard-coded password for a special database account created during Comarch ERP XL installation. This allows an attacker to retrieve embedded sensitive data stored in the database. The password is the same among all Comarch ERP XL installations.
Recommendations
For Comarch ERP XL versions 2020.2.2 through 2023.2, consider changing the hard-coded password for the special database account to a unique and secure password to prevent unauthorized access to sensitive data. As a temporary workaround, restrict access to the database account until a secure password can be implemented.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comarch Erp Xl