First published: Thu Nov 05 2020(Updated: )
Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Self Service Password Reset | >=4.4.0.0<=4.4.0.6 | |
Microfocus Self Service Password Reset | >=4.5.0.1<=4.5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25837 is classified as a medium severity vulnerability that allows the potential disclosure of sensitive information.
CVE-2020-25837 affects Micro Focus Self Service Password Reset versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 to 4.5.0.2.
To mitigate CVE-2020-25837, upgrade to a version of Micro Focus Self Service Password Reset that is not vulnerable.
CVE-2020-25837 is classified as a sensitive information disclosure vulnerability.
Exploitation of CVE-2020-25837 could result in unauthorized access to sensitive user information in certain configurations.