CVE-2022-41399

HIGH

Sage 300 < 2022 - Use of Hard-coded Credentials in Web Screens Database Configuration

Title source: llm
STIX 2.1

Description

The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to the SQL database.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0058
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
sage/sage_300 < 2022
Published Apr 28, 2023
Tracked Since Feb 18, 2026