{"api_version":"1","generated_at":"2026-07-23T12:07:55+00:00","cve":"CVE-2020-10097","urls":{"html":"https://cve.report/CVE-2020-10097","api":"https://cve.report/api/cve/CVE-2020-10097.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-10097","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-10097"},"summary":{"title":"CVE-2020-10097","description":"An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-05 01:15:00","updated_at":"2020-03-05 19:16:00"},"problem_types":["CWE-209"],"metrics":[],"references":[{"url":"https://zammad.com/news/security-advisory-zaa-2020-10","name":"https://zammad.com/news/security-advisory-zaa-2020-10","refsource":"MISC","tags":["Patch","Vendor Advisory"],"title":"Zammad – Helpdesk & Support Software | Zammad Security Advisory ZAA-2020-10","mime":"image/svg+xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-10097","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10097","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"10097","vulnerable":"1","versionEndIncluding":"3.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zammad","cpe5":"zammad","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-10097","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://zammad.com/news/security-advisory-zaa-2020-10","refsource":"MISC","name":"https://zammad.com/news/security-advisory-zaa-2020-10"}]}},"nvd":{"publishedDate":"2020-03-05 01:15:00","lastModifiedDate":"2020-03-05 19:16:00","problem_types":["CWE-209"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndIncluding":"3.2.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"10097","Ordinal":"170493","Title":"CVE-2020-10097","CVE":"CVE-2020-10097","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"10097","Ordinal":"1","NoteData":"An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in successfully exploiting other vulnerabilities.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"10097","Ordinal":"2","NoteData":"2020-03-04","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"10097","Ordinal":"3","NoteData":"2020-03-04","Type":"Other","Title":"Modified"}]}}}