CVE-2024-4995: Asseco Business Solutions S.a Wapro ERP Desktop

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0.

Affected products

Published 2024-12-18. Last modified 2026-06-17.