CVE-2020-7196
—CVSS 3.1
6.5 medium
EPSS
<1%p56
Published
()
Modified
Description
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".
- Vendors
- hp
- Products
- bluedata epic, ezmeral container platform
- Weakness
- CWE-200, CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.