VYPR
High severity7.5NVD Advisory· Published Apr 28, 2023· Updated Jun 17, 2026

CVE-2022-41398

CVE-2022-41398

Description

The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.

Affected products

4
  • cpe:2.3:a:sage:sage_300:*:*:*:*:*:*:*:*
    Range: <=2022
  • Sage/Sagecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2022
  • Apache/Solrllm-fuzzy
    Range: <=2022

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.