CVE Vulnerabilities

CVE-2023-30222

Improper Certificate Validation

Published: Jun 16, 2023 | Modified: Dec 14, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Server 4d 17 (including) 17 (including)
Server 4d 18 (including) 18 (including)
Server 4d 18-r5 (including) 18-r5 (including)
Server 4d 19 (including) 19 (including)
Server 4d 19-r7 (including) 19-r7 (including)

Potential Mitigations

References