An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections cleartext password via the test connection function.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jedox | Jedox | 2020.2.5 (including) | 2020.2.5 (including) |
Jedox_cloud | Jedox | - (including) | - (including) |