Role-based Access Control Flaw in Sage 300 by Sage Software
CVE-2023-29927

4.3MEDIUM

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
16 May 2023

What is CVE-2023-29927?

Sage 300 suffers from a significant access control vulnerability due to role-based access being enforced only on the client side. This flaw allows low-privileged users, particularly in configurations like 'Windows Peer-to-Peer Network' or 'Client Server Network', to gain unauthorized access to the underlying database. These users can retrieve sensitive SQL connection strings, enabling them to create, update, or delete any company records without adhering to the designed role-based restrictions. Organizations using affected versions of Sage 300 must take immediate action to mitigate this risk and safeguard their data.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.