CVE-2022-47880 is an information disclosure vulnerability in Jedox 2020.2.5 and Jedox Cloud, allowing authenticated users with specific permissions to expose cleartext database passwords. Rated MEDIUM (CVSS 5.3), this vulnerability requires low privileges and high attack complexity, but can lead to complete confidentiality compromise. While not listed in CISA's KEV catalog and with no active exploitation or significant community discussion, a public exploit (EDB-51429) exists, demonstrating its potential for credential exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2020.2.5CPE matchmatch criteria | cpe:2.3:a:jedox:jedox:2020.2.5:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:jedox:jedox_cloud:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.