User Password and SQL Connection Strings Vulnerability in Sage 300
CVE-2022-41400

9.8CRITICAL

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
28 April 2023

What is CVE-2022-41400?

Sage 300, through 2022, is affected by a vulnerability where a hard-coded 40-byte Blowfish key is employed for encrypting user passwords and SQL connection strings within ISAM database files. This design flaw potentially permits unauthorized decryption of sensitive credentials stored in the shared data directory, thereby exposing user accounts and SQL connections to malicious actors.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.