Vulnerability Description
Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Veritas | Aptare | < 10.5 |
Related Weaknesses (CWE)
References
- https://www.veritas.com/content/support/en_US/security/VTS20-006#issue2Vendor Advisory
- https://www.veritas.com/content/support/en_US/security/VTS20-006#issue2Vendor Advisory
FAQ
What is CVE-2020-27157?
CVE-2020-27157 is a vulnerability with a CVSS score of 8.1 (HIGH). Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to ...
How severe is CVE-2020-27157?
CVE-2020-27157 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27157?
Check the references section above for vendor advisories and patch information. Affected products include: Veritas Aptare.