CVE-2022-41397: Critical severity sage 300 vulnerability
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41397?
CVE-2022-41397 is a vulnerability in the optional Web Screens and Global Search features for Sage 300 through version 2022 that uses a hard-coded blowfish key for encryption.
How does CVE-2022-41397 affect Sage 300?
CVE-2022-41397 affects Sage 300 through version 2022.
What is the severity of CVE-2022-41397?
CVE-2022-41397 has a severity rating of 9.8 (Critical).
How does CVE-2022-41397 encrypt and decrypt secrets?
CVE-2022-41397 uses a hard-coded blowfish key, "LandlordPassKey", to encrypt and decrypt secrets stored in configuration files and database tables.
Where can I find more information about Sage 300?
You can find more information about Sage 300 on the official Sage website: https://www.sage.com/en-ca/products/sage-300/