Hard-Coded Credential Vulnerability in Sage 300 from Sage
CVE-2022-41398
7.5HIGH
What is CVE-2022-41398?
The Global Search feature in Sage 300 up to version 2022 employs hard-coded credentials for its associated Apache Solr instance. This security lapse could empower attackers to gain unauthorized access to the Solr dashboard with administrative rights, potentially compromising sensitive data and undermining the integrity of the entire system.
