Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-28T00:00:00

Updated: 2024-08-03T12:42:46.205Z

Reserved: 2022-09-26T00:00:00

Link: CVE-2022-41400

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-28T13:15:13.560

Modified: 2023-05-05T18:03:05.717

Link: CVE-2022-41400

cve-icon Redhat

No data.