caterease.com
http://caterease.com/ CVE-2024-38881
HIGH
Record summary
CVE-2024-38881 has a selected CVSS score of 7.5 (high).
Description
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
catereaseBrowse horizoncloud / catereaseDefault status: unknown | CVE List | 16.0.1.1663 to ≤ 24.0.1.2405 | affected |
References
5horizon.com
http://horizon.com/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38881 packetstormsecurity.com
https://packetstormsecurity.com/files/179892/Caterease-Software-SQL-Injection-Command-Injection-Bypass.html vuldb.com
https://vuldb.com/?id.273365