RSS   Vulnerabilities for 'Self service password reset'   RSS

2020-11-05
 
CVE-2020-25837

CWE-200
 

 
Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

 
2019-06-24
 
CVE-2019-11648

 

 
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information.

 
 
CVE-2019-11647

CWE-79
 

 
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.

 
2016-03-23
 
CVE-2016-1599

 

 
Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

 

 >>> Vendor: Netiq 15 Products
Edirectory
Imanager
Pssecure
Identity manager
Access manager
Security manager
Sentinel
Privileged user manager
Sentinel agent manager
Security solutions for iseries
Self service password reset
Access governance suite
Sentinel server
Privileged account manager
Identity reporting


Copyright 2024, cxsecurity.com

 

Back to Top