CRITICAL🇵🇱 Wersja polska

CVE-2020-25256

CVSS 9.1v3.1pub. 2020-09-11upd. 2024-11-21

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across different customers' installations.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Hyland Onbase

    APP
    Hyland
    ≤ 16.0.2.8317.0.0.0 – 17.0.2.10918.0.0.0 – 18.0.0.3719.0.0.0 – 19.8.16.100020.0.0.0 – 20.3.10.1000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-25254CRITICAL9.8PL ✓same product

SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych

CVE-2020-25257CRITICAL9.8PL ✓same product

XXE w Hyland OnBase — nieautoryzowany odczyt i zapis plików

CVE-2020-25253CRITICAL9.8PL ✓same product

SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji

CVE-2020-25251CRITICAL9.1PL ✓same product

Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta

CVE-2020-25258CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu przez niebezpieczną deserializację w Hyland OnBase