CVE-2020-11849
Elevation of privilege and unauthorized access in Micro Focus Identity Manager product
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.
Una elevación de privilegios y/o vulnerabilidad de acceso no autorizado en Micro Focus Identity Manager. Afecta las versiones anteriores a 4.7.3 y 4.8.1 hotfix 1. La vulnerabilidad podría permitir una exposición de información que puede resultar en una elevación de privilegios o un acceso no autorizado
*Credits:
Mark van Reijn, of IDFocus.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-04-16 CVE Reserved
- 2020-07-08 CVE Published
- 2023-03-24 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Identity Manager Search vendor "Microfocus" for product "Identity Manager" | < 4.7.3 Search vendor "Microfocus" for product "Identity Manager" and version " < 4.7.3" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Identity Manager Search vendor "Microfocus" for product "Identity Manager" | 4.7.4 Search vendor "Microfocus" for product "Identity Manager" and version "4.7.4" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Identity Manager Search vendor "Microfocus" for product "Identity Manager" | 4.8.1 Search vendor "Microfocus" for product "Identity Manager" and version "4.8.1" | - |
Affected
|