An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
https://packetstormsecurity.com
https://blog.4d.com/security-bulletin-two-cves-and-how-to-stay-secure/