CVE-2022-47874 is an Improper Access Control vulnerability in Jedox 2020.2.5, affecting Jedox Cloud and Jedox Jedox products. This flaw allows remote authenticated users to view sensitive database connection details by exploiting the /tc/rpc endpoint. Rated Medium severity (CVSS 6.5), it has a low attack complexity and requires authentication, but grants high confidentiality impact by exposing critical information. While not actively exploited in the wild and not on the KEV catalog, a public exploit (EDB-51428) exists, and its FAUCET Risk Score of 96/100 indicates a significant potential risk despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:jedox:cloud:-:*:*:*:*:*:*:* | ||
2020.2.5CPE matchmatch criteria | cpe:2.3:a:jedox:jedox:2020.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.