CVE-2026-96548: sfturing hosp_order jdbc.properties hard-coded credentials
A flaw has been found in sfturing hosporder up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssmpro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or local access?
The vulnerability is described as remotely exploitable and requires no privileges or user interaction. Exploitation is rated high complexity and difficult, despite a published exploit being available.
How can I determine whether my deployment is affected?
Check whether your deployed source includes ssm_pro/src/main/resources/jdbc.properties and whether it is based on code at or before commit 627f426331da8086ce8fff2017d65b1ddef384f8. The advisory does not provide affected release versions because the project uses a rolling release model.
Is a fixed release available?
No affected or updated release versions are identified. The project was reportedly notified through an issue report but had not responded at the time of publication.