First published: Wed Aug 14 2019(Updated: )
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ Self Service Password Reset | >=4.2.0.0<4.2.0.6 | |
Micro Focus NetIQ Self Service Password Reset | >=4.3.0.0<4.3.0.6 | |
Micro Focus NetIQ Self Service Password Reset | >=4.4.0.0<4.4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11652 has a medium severity level due to the potential authorization bypass issue.
To fix CVE-2019-11652, upgrade to Micro Focus Self Service Password Reset (SSPR) versions 4.4.0.3, 4.3.0.6, or 4.2.0.6.
CVE-2019-11652 affects versions of Micro Focus Self Service Password Reset prior to 4.4.0.3, 4.3.0.6, and 4.2.0.6.
CVE-2019-11652 may allow unauthorized users to access sensitive functionality, compromising user security.
There are no documented workarounds for CVE-2019-11652; the recommended mitigation is to upgrade to a secure version.