Описание
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.
Ссылки
- Product
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:jedox:jedox:2020.2.5:*:*:*:*:*:*:*
cpe:2.3:a:jedox:jedox_cloud:-:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.009
Низкий
5.3 Medium
CVSS3
6.8 Medium
CVSS3
Дефекты
CWE-522
CWE-522
Связанные уязвимости
CVSS3: 5.3
github
больше 2 лет назад
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.
EPSS
Процентиль: 75%
0.009
Низкий
5.3 Medium
CVSS3
6.8 Medium
CVSS3
Дефекты
CWE-522
CWE-522