Lucene search

K
cvelistRedhatCVELIST:CVE-2020-25680
HistoryJan 07, 2021 - 5:32 p.m.

CVE-2020-25680

2021-01-0717:32:50
CWE-295
redhat
www.cve.org
1

0.001 Low

EPSS

Percentile

22.7%

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file’s ID is ‘unknown’. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

CNA Affected

[
  {
    "product": "JBCS httpd",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "JBCS httpd 2.4.37 SP5"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

22.7%

Related for CVELIST:CVE-2020-25680