CVE Vulnerabilities

CVE-2020-25249

Published: Sep 11, 2020 | Modified: Jun 30, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.

Affected Software

Name Vendor Start Version End Version
Onbase Hyland * 16.0.2.83 (including)
Onbase Hyland 17.0.0.0 (including) 17.0.2.109 (including)
Onbase Hyland 18.0.0.0 (including) 18.0.0.37 (including)
Onbase Hyland 19.0.0.0 (including) 19.8.16.1000 (including)
Onbase Hyland 20.0.0.0 (including) 20.3.10.1000 (including)

References