Comarch ERP XL client is vulnerable to MS SQL protocol...
High severity
Unreviewed
Published
Feb 15, 2024
to the GitHub Advisory Database
•
Updated Oct 10, 2024
Description
Published by the National Vulnerability Database
Feb 15, 2024
Published to the GitHub Advisory Database
Feb 15, 2024
Last updated
Oct 10, 2024
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
References