comarch CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

comarch vulnerability overview

Aggregates CVE and security vulnerability intelligence across all comarch-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-4539 Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from 2020.2.2 through 2023.2. [email protected] 7.5 0.08% 2024-02-15 2025-01-23
CVE-2023-4538 The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2. [email protected] 6.2 0.05% 2024-02-15 2025-01-23
CVE-2023-4537 Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 through 2023.2. [email protected] 7.4 0.11% 2024-02-15 2025-12-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence