CVE-2019-14886
CVE-2019-14886
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.6EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 mar 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Productos afectados
Red Hat · Business-central¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →