Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-9523

Опубликовано: 17 апр. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microfocus:enterprise_developer:*:*:*:*:*:*:*:*
Версия до 3.0 (включая)
cpe:2.3:a:microfocus:enterprise_developer:4.0:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_10:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_11:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_12:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_13:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_14:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_15:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_3:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_4:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_5:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_6:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_7:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_8:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update_9:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:update_1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:update_2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:update_3:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:update_4:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:5.0:update_5:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:microfocus:enterprise_server:*:*:*:*:*:*:*:*
Версия до 3.0 (включая)
cpe:2.3:a:microfocus:enterprise_server:4.0:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_10:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_11:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_12:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_13:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_14:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_15:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_3:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_4:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_5:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_6:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_7:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_8:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update_9:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:update_1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:update_2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:update_3:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:update_4:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:5.0:update_5:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00288
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-522

Связанные уязвимости

github
больше 3 лет назад

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.

EPSS

Процентиль: 52%
0.00288
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-522