Lucene search

K
cveMitreCVE-2020-25250
HistorySep 11, 2020 - 3:15 a.m.

CVE-2020-25250

2020-09-1103:15:12
mitre
web.nvd.nist.gov
34
2
hyland
onbase
cve-2020-25250
security issue
server logs
data write vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.9%

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client applications can write arbitrary data to the server logs.

Affected configurations

Nvd
Node
hylandonbaseRange16.0.2.83
OR
hylandonbaseRange17.0.0.017.0.2.109
OR
hylandonbaseRange18.0.0.018.0.0.37
OR
hylandonbaseRange19.0.0.019.8.16.1000
OR
hylandonbaseRange20.0.0.020.3.10.1000
VendorProductVersionCPE
hylandonbase*cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.9%

Related for CVE-2020-25250