CVE-2020-25256: Critical severity hyland onbase vulnerability
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across different customers' installations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25256?
CVE-2020-25256 has a high severity rating due to the risk of compromised security through shared PKI certificate private keys.
How do I fix CVE-2020-25256?
To fix CVE-2020-25256, update Hyland OnBase to a version above the specified vulnerable versions listed in the advisory.
What impact does CVE-2020-25256 have on my system?
The impact of CVE-2020-25256 includes potential unauthorized access and data exposure due to the shared private keys across installations.
Which versions of Hyland OnBase are affected by CVE-2020-25256?
Hyland OnBase versions 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below, and 20.3.10.1000 and below are affected by CVE-2020-25256.
Is there a risk of exploitation for CVE-2020-25256?
Yes, CVE-2020-25256 poses a significant risk of exploitation due to the potential for attackers to utilize the common private key across different customer installations.