Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41400


Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.


Published

2023-04-28T13:15:13.560

Last Modified

2025-01-30T21:15:09.157

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-798
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sage sage_300 ≤ 2022 Yes

References