CVE-2020-25249: Medium severity hyland onbase vulnerability
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Hyland OnBase?
The vulnerability ID for this issue in Hyland OnBase is CVE-2020-25249.
What versions of Hyland OnBase are affected by this vulnerability?
Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below, and 20.3.10.1000 and below are affected by this vulnerability.
How severe is the vulnerability with ID CVE-2020-25249?
The severity of the vulnerability with ID CVE-2020-25249 is medium with a CVSS score of 5.3.
What is the impact of this vulnerability in Hyland OnBase?
The impact of this vulnerability in Hyland OnBase is the potential for logged activity to be accessed by unauthorized users.
Is there a fix available for the vulnerability with ID CVE-2020-25249?
Yes, there is a fix available for the vulnerability with ID CVE-2020-25249. It is recommended to update to a version of Hyland OnBase that is not affected by the vulnerability.