First published: Fri Nov 13 2020(Updated: )
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oneidentity Password Manager | =5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-7962.
One Identity Password Manager 5.8 is affected by this vulnerability.
The severity of CVE-2020-7962 is medium with a severity value of 5.3.
The CWE ID associated with this vulnerability is 203.
An attacker can exploit this vulnerability by enumerating valid answers for a user and reusing them for a password reset on a chosen password.