Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.
References
| Link | Resource |
|---|---|
| https://www.netiq.com/documentation/self-service-password-reset-44/release-notes-sspr-44-p7/data/release-notes-sspr-44-p7.html | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-11-05 21:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-25837
Mitre link : CVE-2020-25837
JSON object : View
Products Affected
microfocus
- self_service_password_reset
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
