CVE-2020-25836 Vulnerability Details

  /     /     /  

CVE-2020-25836 Metadata Quick Info

CVE Published: 16/07/2024 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: OpenText | Vendor: OpenText | Product: NetIQ Directory and Resource Administrator
Status : PUBLISHED

CVE-2020-25836 Description

Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10.

Metrics

CVSS Version: 3.1 | Base Score: 6.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-200
CWE Name: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Source: OpenText

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-410
CAPEC Description: CAPEC-410 Information Elicitation


Source: NVD (National Vulnerability Database).