← Back

CVE-2020-7196

nvd nist
Published: Oct 26, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

Affected (2)

2 products
Bluedata Epic
Ezmeral Container Platform
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.0
Version 5.0

Timeline

No history available yet.