8.8

CVE-2020-9523

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Enterprise Developer Version <= 3.0
Microfocus ≫ Enterprise Developer Version 4.0 Update -
Microfocus ≫ Enterprise Developer Version 4.0 Update update_1
Microfocus ≫ Enterprise Developer Version 4.0 Update update_10
Microfocus ≫ Enterprise Developer Version 4.0 Update update_11
Microfocus ≫ Enterprise Developer Version 4.0 Update update_12
Microfocus ≫ Enterprise Developer Version 4.0 Update update_13
Microfocus ≫ Enterprise Developer Version 4.0 Update update_14
Microfocus ≫ Enterprise Developer Version 4.0 Update update_15
Microfocus ≫ Enterprise Developer Version 4.0 Update update_2
Microfocus ≫ Enterprise Developer Version 4.0 Update update_3
Microfocus ≫ Enterprise Developer Version 4.0 Update update_4
Microfocus ≫ Enterprise Developer Version 4.0 Update update_5
Microfocus ≫ Enterprise Developer Version 4.0 Update update_6
Microfocus ≫ Enterprise Developer Version 4.0 Update update_7
Microfocus ≫ Enterprise Developer Version 4.0 Update update_8
Microfocus ≫ Enterprise Developer Version 4.0 Update update_9
Microfocus ≫ Enterprise Developer Version 5.0 Update -
Microfocus ≫ Enterprise Developer Version 5.0 Update update_1
Microfocus ≫ Enterprise Developer Version 5.0 Update update_2
Microfocus ≫ Enterprise Developer Version 5.0 Update update_3
Microfocus ≫ Enterprise Developer Version 5.0 Update update_4
Microfocus ≫ Enterprise Developer Version 5.0 Update update_5
Microfocus ≫ Enterprise Server Version <= 3.0
Microfocus ≫ Enterprise Server Version 4.0 Update -
Microfocus ≫ Enterprise Server Version 4.0 Update update_1
Microfocus ≫ Enterprise Server Version 4.0 Update update_10
Microfocus ≫ Enterprise Server Version 4.0 Update update_11
Microfocus ≫ Enterprise Server Version 4.0 Update update_12
Microfocus ≫ Enterprise Server Version 4.0 Update update_13
Microfocus ≫ Enterprise Server Version 4.0 Update update_14
Microfocus ≫ Enterprise Server Version 4.0 Update update_15
Microfocus ≫ Enterprise Server Version 4.0 Update update_2
Microfocus ≫ Enterprise Server Version 4.0 Update update_3
Microfocus ≫ Enterprise Server Version 4.0 Update update_4
Microfocus ≫ Enterprise Server Version 4.0 Update update_5
Microfocus ≫ Enterprise Server Version 4.0 Update update_6
Microfocus ≫ Enterprise Server Version 4.0 Update update_7
Microfocus ≫ Enterprise Server Version 4.0 Update update_8
Microfocus ≫ Enterprise Server Version 4.0 Update update_9
Microfocus ≫ Enterprise Server Version 5.0 Update -
Microfocus ≫ Enterprise Server Version 5.0 Update update_1
Microfocus ≫ Enterprise Server Version 5.0 Update update_2
Microfocus ≫ Enterprise Server Version 5.0 Update update_3
Microfocus ≫ Enterprise Server Version 5.0 Update update_4
Microfocus ≫ Enterprise Server Version 5.0 Update update_5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.