ZeroHour

CVE-2019-12121

PoC
CVSS 3.1
7.5 high
EPSS
<1%p52
Published
()
Modified
Description

An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.

Vendors
onap
Products
open network automation platform
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.