HIGH

CVE-2021-44207

Acclaimsystems Usaherds 2021-12-21 CVSS v3.1
CVSS
8.1
KEV

Description

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

Summary dbcve.org

The Acclaim USAHERDS application through version 7.4.0.1 contains hard-coded credentials embedded directly in the source code. These credentials can be extracted by anyone with access to the application binary or source code, potentially allowing unauthorized access to the system or associated services.

Mitigation

Remove all hard-coded credentials from the codebase and implement a secure secrets management solution such as environment variables, a secrets manager (e.g., HashiCorp Vault, Azure Key Vault), or a configuration management system. Rotate any credentials that may have been exposed.

Weakness (CWE)

CWE-798 Hard-coded Credentials

EPSS Score

17.58%
Probability of exploitation in next 30 days
97th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE