Description
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords.

This issue affects ERP XL: from 2020.2.2 through 2023.2.
Published: 2024-02-15
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54393 The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.
History

Thu, 23 Jan 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Comarch
Comarch erp Xl
CPEs cpe:2.3:a:comarch:erp_xl:*:*:*:*:*:*:*:*
Vendors & Products Comarch
Comarch erp Xl

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2024-08-29T18:01:40.861Z

Reserved: 2023-08-25T11:18:57.053Z

Link: CVE-2023-4538

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.531Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-15T09:15:33.557

Modified: 2025-01-23T17:17:07.870

Link: CVE-2023-4538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses