Comarch's vulnerability footprint centers on its ERP XL enterprise resource planning platform, a modestly deployed business system where the durable signal reflects application-layer weaknesses in exception handling, credential management, and hard-coded authentication material. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comarch over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4537HIGH Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and mod | Feb 15, 2024 | 7.4 | 23 | NO | NO |
CVE-2023-4539HIGH Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database | Feb 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-4538MEDIUM The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installation | Feb 15, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comarch.
Media articles that mention a CVE ID that affects a product developed by Comarch — matched by CVE ID, not by vendor name.