Access Control Flaw in Sage 300 Affects User Credentials and SQL Database
CVE-2022-38583

7.8HIGH

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
28 April 2023

What is CVE-2022-38583?

A vulnerability exists in Sage 300 versions 2017 through 2022 when configured in Windows Peer-to-Peer or Client Server Network modes. Low-privileged users can exploit their access to the SharedData folder on the server to view and modify user credentials, including those of Sage 300 users and SQL accounts. This could allow unauthorized impersonation of other users or access to the SQL database as a system administrator, potentially enabling the attacker to create, update, and delete records or execute arbitrary code on the underlying database server.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.