Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27157


Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.


Published

2020-10-15T05:15:12.337

Last Modified

2024-11-21T05:20:47.937

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-294

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application veritas aptare < 10.5 Yes

References