CVE Vulnerabilities

CVE-2022-47874

Published: May 02, 2023 | Modified: May 10, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class com.jedox.etl.mngr.Connections and method getGlobalConnection.

Affected Software

Name Vendor Start Version End Version
Cloud Jedox - (including) - (including)
Jedox Jedox 2020.2.5 (including) 2020.2.5 (including)

References