PT-2024-26862 · Microsoft+1 · Windows+1

Published

2024-05-24

·

Updated

2024-08-26

·

CVE-2024-36049

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aptos Wisal payroll accounting versions prior to 7.1.6
Description The issue allows attackers in a machine-in-the-middle position to gain read and write access to personally identifiable information (PII) and payroll data. It also enables them to impersonate legitimate users with respect to the audit log. This is due to the use of hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server over an unencrypted connection.
Recommendations For versions prior to 7.1.6, update to version 7.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the database server or using an encrypted connection to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-36049

Affected Products

Aptos Wisal Payroll Accounting
Windows