CVE-2022-47874
MEDIUMJedox Cloud - Incorrect Authorization
Title source: ruleDescription
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.2847
EPSS Percentile
96.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-863
Status
published
Products (2)
jedox/cloud
jedox/jedox
2020.2.5
Published
May 02, 2023
Tracked Since
Feb 18, 2026