An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.
                
            References
                    | Link | Resource | 
|---|---|
| http://caterease.com | Product | 
| http://horizon.com | Not Applicable | 
| https://vuldb.com/?id.273369 | VDB Entry Permissions Required | 
Configurations
                    History
                    13 May 2025, 14:11
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Horizoncloud Horizoncloud caterease | |
| CPE | cpe:2.3:a:horizoncloud:caterease:*:*:*:*:*:*:*:* | |
| References | () http://caterease.com - Product | |
| References | () http://horizon.com - Not Applicable | |
| References | () https://vuldb.com/?id.273369 - VDB Entry, Permissions Required | 
Information
                Published : 2024-08-02 18:16
Updated : 2025-05-13 14:11
NVD link : CVE-2024-38885
Mitre link : CVE-2024-38885
CVE.ORG link : CVE-2024-38885
JSON object : View
Products Affected
                horizoncloud
- caterease
CWE
                
                    
                        
                        CWE-259
                        
            Use of Hard-coded Password
