Vulnerabilities > Thomsonreuters > Ultratax CS 2017

DATE CVE VULNERABILITY TITLE RISK
2018-07-26 CVE-2018-14607 Missing Encryption of Sensitive Data vulnerability in Thomsonreuters Ultratax CS 2017
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
network
low complexity
thomsonreuters CWE-311
7.5