CVE-2025-68421
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-798
Credenciales embebidas en el software
Fecha de publicación:
14/05/2026
Última modificación:
14/05/2026
Descripción
*** Pendiente de traducción *** Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.<br />
This issue has been fixed in version 2026.4
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA



