Vulnerability Details CVE-2023-4537
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification.
This issue affects ERP XL: from 2020.2.2 through 2023.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.6%
CVSS Severity
CVSS v3 Score 7.4
Products affected by CVE-2023-4537
-
cpe:2.3:a:comarch:erp_xl:2020.2.2
-
cpe:2.3:a:comarch:erp_xl:2022.0
-
cpe:2.3:a:comarch:erp_xl:2022.0.1
-
cpe:2.3:a:comarch:erp_xl:2022.0.2
-
cpe:2.3:a:comarch:erp_xl:2022.1
-
cpe:2.3:a:comarch:erp_xl:2023.0
-
cpe:2.3:a:comarch:erp_xl:2023.1
-
cpe:2.3:a:comarch:erp_xl:2023.2