An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
| Software | From | Fixed in |
|---|---|---|
| 4d / server | 18 | 18.x |
| 4d / server | 18-r5 | 18-r5.x |
| 4d / server | 19 | 19.x |
| 4d / server | 19-r7 | 19-r7.x |
| 4d / server | 17 | 17.x |