An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28881 An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T09:48:24.779Z

Reserved: 2020-01-24T00:00:00

Link: CVE-2020-7962

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-13T19:15:12.173

Modified: 2024-11-21T05:38:05.957

Link: CVE-2020-7962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses