CVE Vulnerabilities

CVE-2020-25837

Published: Nov 05, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Self_service_password_resetMicrofocus4.4.0.0 (including)4.4.0.6 (including)
Self_service_password_resetMicrofocus4.5.0.1 (including)4.5.0.2 (including)

References