Impact
Streamsoft Business Intelligence stores user passwords in plaintext within its database. This flaw allows any actor with database read access to obtain clear‑text passwords, compromising account authenticity and potentially exposing users to credential reuse attacks. The vulnerability is recognized as CWE‑256.
Affected Systems
All instances of Streamsoft Business Intelligence released before version 6.8.0.0 are affected. The issue was fixed in version 6.8.0.0. Users are encouraged to upgrade to the newest release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact severity; however, the EPSS of less than 1% and absence from CISA KEV suggest that exploitation is unlikely at present. An attacker must gain database access or exploit another vulnerability to read the credentials, but once achieved, the data exposure could compromise multiple user accounts.
OpenCVE Enrichment