CVE-2024-38885
Severity CVSS v4.0:
Pending analysis
Type:
CWE-259
Use of Hard-coded Password
Publication date:
02/08/2024
Last modified:
13/05/2025
Description
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:horizoncloud:caterease:*:*:*:*:*:*:*:* | 16.0.1.1663 (including) | 24.0.1.2405 (including) |
To consult the complete list of CPE names with products and versions, see this page



