Known Vulnerabilities for Sage 300 by Sage
Listed below are 7 of the newest known vulnerabilities associated with "Sage 300" by "Sage".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-67807 json | The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-67806 json | The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-67805 json | A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2024-52384 json | Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle... | Not Provided | 2024-11-14 | 2026-04-01 |
| CVE-2023-29927 json | Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privileged Sag... | 4.3 - MEDIUM | 2023-05-16 | 2023-05-25 |
| CVE-2022-41400 json | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings... | 9.8 - CRITICAL | 2023-04-28 | 2023-05-05 |
| CVE-2022-41399 json | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to enc... | 7.5 - HIGH | 2023-04-28 | 2023-05-05 |
| CVE-2022-41398 json | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanyin... | 7.5 - HIGH | 2023-04-28 | 2023-05-05 |
| CVE-2022-41397 json | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key (... | 9.8 - CRITICAL | 2023-04-28 | 2023-05-05 |
| CVE-2022-38583 json | On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Net... | 7.8 - HIGH | 2023-04-28 | 2023-05-05 |