Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58qw-vfcj-x2hg

Опубликовано: 15 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.

This issue affects ERP XL: from 2020.2.2 through 2023.2.

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.

This issue affects ERP XL: from 2020.2.2 through 2023.2.

EPSS

Процентиль: 30%
0.00113
Низкий

7.4 High

CVSS3

Дефекты

CWE-311
CWE-755

Связанные уязвимости

CVSS3: 7.4
nvd
почти 2 года назад

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 through 2023.2.

EPSS

Процентиль: 30%
0.00113
Низкий

7.4 High

CVSS3

Дефекты

CWE-311
CWE-755