First published: Fri Jun 16 2023(Updated: )
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
4D Server | =17 | |
4D Server | =18 | |
4D Server | =18-r5 | |
4D Server | =19 | |
4D Server | =19-r7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-30222.
The severity of CVE-2023-30222 is high with a severity value of 7.5.
CVE-2023-30222 allows attackers to retrieve password hashes for all users via eavesdropping in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier versions.
To fix CVE-2023-30222, it is recommended to update to the latest version (v19 R8 or later) of 4D SAS 4D Server Application.
You can find more information about CVE-2023-30222 at the following references: [link](https://packetstormsecurity.com) and [link](https://www.infigo.is/en/insights/42/information-disclosure-and-broken-authentication-in-4d-sas-4d-server/).