8.8

CVE-2020-9523

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.

Data is provided by the National Vulnerability Database (NVD)
MicrofocusEnterprise Developer Version <= 3.0
MicrofocusEnterprise Developer Version4.0 Update-
MicrofocusEnterprise Developer Version4.0 Updateupdate_1
MicrofocusEnterprise Developer Version4.0 Updateupdate_10
MicrofocusEnterprise Developer Version4.0 Updateupdate_11
MicrofocusEnterprise Developer Version4.0 Updateupdate_12
MicrofocusEnterprise Developer Version4.0 Updateupdate_13
MicrofocusEnterprise Developer Version4.0 Updateupdate_14
MicrofocusEnterprise Developer Version4.0 Updateupdate_15
MicrofocusEnterprise Developer Version4.0 Updateupdate_2
MicrofocusEnterprise Developer Version4.0 Updateupdate_3
MicrofocusEnterprise Developer Version4.0 Updateupdate_4
MicrofocusEnterprise Developer Version4.0 Updateupdate_5
MicrofocusEnterprise Developer Version4.0 Updateupdate_6
MicrofocusEnterprise Developer Version4.0 Updateupdate_7
MicrofocusEnterprise Developer Version4.0 Updateupdate_8
MicrofocusEnterprise Developer Version4.0 Updateupdate_9
MicrofocusEnterprise Developer Version5.0 Update-
MicrofocusEnterprise Developer Version5.0 Updateupdate_1
MicrofocusEnterprise Developer Version5.0 Updateupdate_2
MicrofocusEnterprise Developer Version5.0 Updateupdate_3
MicrofocusEnterprise Developer Version5.0 Updateupdate_4
MicrofocusEnterprise Developer Version5.0 Updateupdate_5
MicrofocusEnterprise Server Version <= 3.0
MicrofocusEnterprise Server Version4.0 Update-
MicrofocusEnterprise Server Version4.0 Updateupdate_1
MicrofocusEnterprise Server Version4.0 Updateupdate_10
MicrofocusEnterprise Server Version4.0 Updateupdate_11
MicrofocusEnterprise Server Version4.0 Updateupdate_12
MicrofocusEnterprise Server Version4.0 Updateupdate_13
MicrofocusEnterprise Server Version4.0 Updateupdate_14
MicrofocusEnterprise Server Version4.0 Updateupdate_15
MicrofocusEnterprise Server Version4.0 Updateupdate_2
MicrofocusEnterprise Server Version4.0 Updateupdate_3
MicrofocusEnterprise Server Version4.0 Updateupdate_4
MicrofocusEnterprise Server Version4.0 Updateupdate_5
MicrofocusEnterprise Server Version4.0 Updateupdate_6
MicrofocusEnterprise Server Version4.0 Updateupdate_7
MicrofocusEnterprise Server Version4.0 Updateupdate_8
MicrofocusEnterprise Server Version4.0 Updateupdate_9
MicrofocusEnterprise Server Version5.0 Update-
MicrofocusEnterprise Server Version5.0 Updateupdate_1
MicrofocusEnterprise Server Version5.0 Updateupdate_2
MicrofocusEnterprise Server Version5.0 Updateupdate_3
MicrofocusEnterprise Server Version5.0 Updateupdate_4
MicrofocusEnterprise Server Version5.0 Updateupdate_5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.519
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.