CVE Vulnerabilities

CVE-2019-14886

Cleartext Storage of Sensitive Information

Published: Mar 05, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Decision_managerRedhat7.5.1 (including)7.5.1 (including)
Process_automation_managerRedhat7.5.1 (including)7.5.1 (including)
Red Hat Decision Manager 7RedHatBusiness-central*
Red Hat Process Automation 7RedHatBusiness-central*

Potential Mitigations

References