CVE-2022-41398
28.04.2023, 13:15
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
sage | sage_300 | 𝑥 ≤ 2022 |
𝑥
= Vulnerable software versions