It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
2022-04-01T23:15:08.533
2024-11-21T04:27:28.403
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | business-central | ≤ 7.48.0 | Yes |
Application | redhat | descision_manager | 7.0 | Yes |
Application | redhat | process_automation | 7.0 | Yes |