vendor:
Jedox
by:
Team Syslifters / Christoph MAHRL, Aron MOLNAR, Patrick PIRKER and Michael WEDL
7.4
CVSS
HIGH
Improper Access Controls
284
CWE
Product Name: Jedox
Affected Version From: Jedox 2020.2 (20.2.5) and older
Affected Version To: Jedox 2020.2 (20.2.5)
Patch Exists: YES
Related CWE: CVE-2022-47874
CPE: a:jedox:jedox
Platforms Tested:
2023
Jedox 2020.2.5 – Disclosure of Database Credentials via Improper Access Controls
Improper access controls in /tc/rpc allows remote authenticated users to view details of database connections via the class com.jedox.etl.mngr.Connections and the method getGlobalConnection. To exploit the vulnerability, the attacker must know the name of the database connection.
Mitigation:
Ensure that access controls are properly configured and that only authorized users are able to access sensitive information.