Skip to main content

Vendor/product archive

comarch / erp_xl CVEs

Beta · best-effort

3 CVEs tagged to comarch / erp_xl0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-4539

Published Feb 15, 2024

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the databas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4538

Published Feb 15, 2024

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installatio…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4537

Published Feb 15, 2024

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and mo…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1