CVE-2022-41397

CRITICAL

Sage 300 < 2022 - Use of Hard-coded Credentials in Web Screens and Global Search

Title source: llm
STIX 2.1

Description

The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
sage/sage_300 < 2022
Published Apr 28, 2023
Tracked Since Feb 18, 2026