CVE-2023-4538
15.02.2024, 09:15
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.Enginsight
Vendor | Product | Version |
---|---|---|
comarch | erp_xl | 2020.2.2 ≤ 𝑥 ≤ 2023.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration