CVE-2020-11631: Medium severity ejbca vulnerability
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation can lead to privilege escalation and remote code execution. (This is exploitable only when at least one accessible port lacks a requirement for client certificate authentication. These ports are 8442 or 8080 in a standard installation.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11631?
CVE-2020-11631 has a severity rating that indicates a critical vulnerability capable of leading to privilege escalation and remote code execution.
How do I fix CVE-2020-11631?
To fix CVE-2020-11631, upgrade EJBCA to version 6.15.2.6 or 7.3.1.2 or later.
What versions of EJBCA are affected by CVE-2020-11631?
EJBCA versions prior to 6.15.2.6 and from 7.0.0 up to 7.3.1.2 are affected by CVE-2020-11631.
Can CVE-2020-11631 be exploited remotely?
Yes, CVE-2020-11631 can be exploited remotely by a malicious user to escalate privileges.
What are the potential impacts of exploiting CVE-2020-11631?
Exploiting CVE-2020-11631 can lead to privilege escalation and remote code execution, putting systems at significant risk.