Vulnerability Description
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oneidentity | Password Manager | 5.8 |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2020050185Third Party Advisory
- https://cxsecurity.com/issue/WLB-2020050185Third Party Advisory
FAQ
What is CVE-2020-7962?
CVE-2020-7962 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response c...
How severe is CVE-2020-7962?
CVE-2020-7962 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7962?
Check the references section above for vendor advisories and patch information. Affected products include: Oneidentity Password Manager.