CVE-2020-25837: High severity microfocus netiq self service password reset vulnerability
Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25837?
CVE-2020-25837 is classified as a medium severity vulnerability that allows the potential disclosure of sensitive information.
What versions of Micro Focus Self Service Password Reset are affected by CVE-2020-25837?
CVE-2020-25837 affects Micro Focus Self Service Password Reset versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 to 4.5.0.2.
How do I fix CVE-2020-25837?
To mitigate CVE-2020-25837, upgrade to a version of Micro Focus Self Service Password Reset that is not vulnerable.
What type of vulnerability is CVE-2020-25837?
CVE-2020-25837 is classified as a sensitive information disclosure vulnerability.
What are the implications of CVE-2020-25837?
Exploitation of CVE-2020-25837 could result in unauthorized access to sensitive user information in certain configurations.