Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Comarch
Comarch erp Xl |
|
CPEs | cpe:2.3:a:comarch:erp_xl:2020.2.2:*:*:*:*:*:*:* | |
Vendors & Products |
Comarch
Comarch erp Xl |
|
References |
|
|
Metrics |
ssvc
|
Thu, 10 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-311 |
Thu, 10 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-755 | |
References |
|
Tue, 27 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-02-15T08:27:07.579Z
Updated: 2024-10-10T15:35:58.278Z
Reserved: 2023-08-25T11:18:53.081Z
Link: CVE-2023-4537
Vulnrichment
Updated: 2024-08-02T07:31:06.324Z
NVD
Status : Awaiting Analysis
Published: 2024-02-15T09:15:33.273
Modified: 2024-11-21T08:35:22.247
Link: CVE-2023-4537
Redhat
No data.