PT-2024-13244 · Comarch · Comarch Erp Xl

Marcin Ochab

·

Published

2024-02-15

·

Updated

2024-02-17

·

CVE-2023-4539

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Comarch ERP XL versions 2020.2.2 through 2023.2
Description The issue is related to the use of a hard-coded password for a special database account created during Comarch ERP XL installation. This allows an attacker to retrieve embedded sensitive data stored in the database. The password is the same among all Comarch ERP XL installations.
Recommendations For Comarch ERP XL versions 2020.2.2 through 2023.2, consider changing the hard-coded password for the special database account to a unique and secure password to prevent unauthorized access to sensitive data. As a temporary workaround, restrict access to the database account until a secure password can be implemented.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-4539

Affected Products

Comarch Erp Xl