8.8
CVE-2020-9523
- EPSS 0.86%
- Veröffentlicht 17.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:48
- Erkennungen
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Enterprise Developer Version <= 3.0
Microfocus ≫ Enterprise Developer Version 4.0 Update -
Microfocus ≫ Enterprise Developer Version 4.0 Update update_1
Microfocus ≫ Enterprise Developer Version 4.0 Update update_10
Microfocus ≫ Enterprise Developer Version 4.0 Update update_11
Microfocus ≫ Enterprise Developer Version 4.0 Update update_12
Microfocus ≫ Enterprise Developer Version 4.0 Update update_13
Microfocus ≫ Enterprise Developer Version 4.0 Update update_14
Microfocus ≫ Enterprise Developer Version 4.0 Update update_15
Microfocus ≫ Enterprise Developer Version 4.0 Update update_2
Microfocus ≫ Enterprise Developer Version 4.0 Update update_3
Microfocus ≫ Enterprise Developer Version 4.0 Update update_4
Microfocus ≫ Enterprise Developer Version 4.0 Update update_5
Microfocus ≫ Enterprise Developer Version 4.0 Update update_6
Microfocus ≫ Enterprise Developer Version 4.0 Update update_7
Microfocus ≫ Enterprise Developer Version 4.0 Update update_8
Microfocus ≫ Enterprise Developer Version 4.0 Update update_9
Microfocus ≫ Enterprise Developer Version 5.0 Update -
Microfocus ≫ Enterprise Developer Version 5.0 Update update_1
Microfocus ≫ Enterprise Developer Version 5.0 Update update_2
Microfocus ≫ Enterprise Developer Version 5.0 Update update_3
Microfocus ≫ Enterprise Developer Version 5.0 Update update_4
Microfocus ≫ Enterprise Developer Version 5.0 Update update_5
Microfocus ≫ Enterprise Server Version <= 3.0
Microfocus ≫ Enterprise Server Version 4.0 Update -
Microfocus ≫ Enterprise Server Version 4.0 Update update_1
Microfocus ≫ Enterprise Server Version 4.0 Update update_10
Microfocus ≫ Enterprise Server Version 4.0 Update update_11
Microfocus ≫ Enterprise Server Version 4.0 Update update_12
Microfocus ≫ Enterprise Server Version 4.0 Update update_13
Microfocus ≫ Enterprise Server Version 4.0 Update update_14
Microfocus ≫ Enterprise Server Version 4.0 Update update_15
Microfocus ≫ Enterprise Server Version 4.0 Update update_2
Microfocus ≫ Enterprise Server Version 4.0 Update update_3
Microfocus ≫ Enterprise Server Version 4.0 Update update_4
Microfocus ≫ Enterprise Server Version 4.0 Update update_5
Microfocus ≫ Enterprise Server Version 4.0 Update update_6
Microfocus ≫ Enterprise Server Version 4.0 Update update_7
Microfocus ≫ Enterprise Server Version 4.0 Update update_8
Microfocus ≫ Enterprise Server Version 4.0 Update update_9
Microfocus ≫ Enterprise Server Version 5.0 Update -
Microfocus ≫ Enterprise Server Version 5.0 Update update_1
Microfocus ≫ Enterprise Server Version 5.0 Update update_2
Microfocus ≫ Enterprise Server Version 5.0 Update update_3
Microfocus ≫ Enterprise Server Version 5.0 Update update_4
Microfocus ≫ Enterprise Server Version 5.0 Update update_5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.537 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://softwaresupport.softwaregrp.com/doc/KM03634936