CVE-2023-4539
Published Feb 15, 2024Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the databas…
Vendor/product archive
3 CVEs tagged to comarch / erp_xl — 0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the databas…
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installatio…
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and mo…