Skip to main content

Vendor/product archive

sage / sage_300 CVEs

Beta · best-effort

7 CVEs tagged to sage / sage_3002 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-29927

Published May 16, 2023

Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privileged Sage users, particularly those on a workstation setup in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41400

Published Apr 28, 2023

Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data dire…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-41399

Published Apr 28, 2023

The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41398

Published Apr 28, 2023

The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41397

Published Apr 28, 2023

The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stor…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-38583

Published Apr 28, 2023

On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 worksta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45492

Published Jul 14, 2022

In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1