VYPR
Unrated severityNVD Advisory· Published Apr 28, 2023· Updated Jan 31, 2025

CVE-2022-41397

CVE-2022-41397

Description

The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.

Affected products

2
  • Sage/Sagecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2022

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.