CVE-2020-7962
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-7962.
What software is affected by this vulnerability?
One Identity Password Manager 5.8 is affected by this vulnerability.
What is the severity of CVE-2020-7962?
The severity of CVE-2020-7962 is medium with a severity value of 5.3.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is 203.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by enumerating valid answers for a user and reusing them for a password reset on a chosen password.