First published: Tue Sep 03 2019(Updated: )
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Decision Manager | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14840 is a vulnerability found in the RedHat Decision Manager (RHDM) software that enables auto-complete for sensitive HTML form fields.
CVE-2019-14840 has a severity rating of 7.5 (high).
CVE-2019-14840 affects RHDM 7.0, allowing auto-complete for sensitive form fields like Password, which may result in credential leakage.
Yes, the fix for CVE-2019-14840 is available from Red Hat. Please refer to the provided references for more information on how to apply the fix.
The Common Weakness Enumeration (CWE) ID for CVE-2019-14840 is CWE-522.