CVE Vulnerabilities

CVE-2019-14886

Cleartext Storage of Sensitive Information

Published: Mar 05, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Ubuntu

A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Decision_manager Redhat 7.5.1 (including) 7.5.1 (including)
Process_automation_manager Redhat 7.5.1 (including) 7.5.1 (including)
Red Hat Decision Manager 7 RedHat Business-central *
Red Hat Process Automation 7 RedHat Business-central *

Potential Mitigations

References