Vulnerabilities (CVE)

Filtered by vendor Thomsonreuters
Filtered by product Ultratax Cs 2017
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14607 1 Thomsonreuters 1 Ultratax Cs 2017 2024-11-21 5.0 MEDIUM 7.5 HIGH
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. The customer record transferred in cleartext contains: Client ID, Full Name, Spouse's Full Name, Social Security Number, Spouse's Social Security Number, Occupation, Spouse's Occupation, D ...

Show More