First published: Tue May 02 2023(Updated: )
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.
Credit: Team Syslifters cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jedox Cloud | ||
Jedox Jedox | =2020.2.5 | |
=2020.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47874 is an improper access control vulnerability in Jedox GmbH Jedox 2020.2.5 that allows remote authenticated users to view details of database connections.
The severity of CVE-2022-47874 is medium with a CVSS score of 6.5.
Remote authenticated users can exploit CVE-2022-47874 by accessing the /tc/rpc endpoint and using the 'com.jedox.etl.mngr.Connections' class and 'getGlobalConnection' method to view database connection details.
Jedox Jedox 2020.2.5 is the affected version.
To fix CVE-2022-47874, it is recommended to update your Jedox software to a version that includes the necessary security patches.