CVE-2019-11674: Medium severity micro focus netiq self service password reset vulnerability
Published Oct 22, 2019
·Updated
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
Affected Software
5 affected components
MicroFocus Netiq Self Service Password Reset<=4.3
MicroFocus Netiq Self Service Password Reset=4.4
MicroFocus Netiq Self Service Password Reset=4.4-update_1
MicroFocus Netiq Self Service Password Reset=4.4-update_2
MicroFocus Netiq Self Service Password Reset=4.4-update_3
Event History
Oct 22, 2019
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11674?
The severity of CVE-2019-11674 is considered high due to the potential for a man-in-the-middle attack.
2
How do I fix CVE-2019-11674?
To fix CVE-2019-11674, upgrade to version 4.4.0.4 or later of Micro Focus Self Service Password Reset.
3
Which versions are affected by CVE-2019-11674?
CVE-2019-11674 affects all versions of Micro Focus Self Service Password Reset prior to 4.4.0.4.
4
What type of attack is enabled by CVE-2019-11674?
CVE-2019-11674 enables a man-in-the-middle attack due to invalid certificate validation.
5
Is there a workaround for CVE-2019-11674?
There are no known workarounds for CVE-2019-11674; the only solution is to upgrade to a patched version.