CVE Vulnerabilities

CVE-2020-25837

Published: Nov 05, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

Affected Software

Name Vendor Start Version End Version
Self_service_password_reset Microfocus 4.4.0.0 (including) 4.4.0.6 (including)
Self_service_password_reset Microfocus 4.5.0.1 (including) 4.5.0.2 (including)

References