{"api_version":"1","generated_at":"2026-04-23T15:08:31+00:00","cve":"CVE-2020-25837","urls":{"html":"https://cve.report/CVE-2020-25837","api":"https://cve.report/api/cve/CVE-2020-25837.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-25837","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-25837"},"summary":{"title":"CVE-2020-25837","description":"Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2020-11-05 21:15:00","updated_at":"2023-11-07 03:20:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.netiq.com/documentation/self-service-password-reset-44/release-notes-sspr-44-p7/data/release-notes-sspr-44-p7.html","name":"https://www.netiq.com/documentation/self-service-password-reset-44/release-notes-sspr-44-p7/data/release-notes-sspr-44-p7.html","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"NetIQ Self Service Password Reset 4.4 Patch Update 7 Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-25837","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25837","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"25837","vulnerable":"1","versionEndIncluding":"4.4.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"self_service_password_reset","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25837","vulnerable":"1","versionEndIncluding":"4.5.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"self_service_password_reset","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-25837","ASSIGNER":"security@microfocus.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Micro Focus Self Service Password Reset (SSPR)","version":{"version_data":[{"version_value":"4.4.0.0  to 4.4.0.6 and 4.5.0.1 and 4.5.0.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"information leakage"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.netiq.com/documentation/self-service-password-reset-44/release-notes-sspr-44-p7/data/release-notes-sspr-44-p7.html","url":"https://www.netiq.com/documentation/self-service-password-reset-44/release-notes-sspr-44-p7/data/release-notes-sspr-44-p7.html"}]},"description":{"description_data":[{"lang":"eng","value":"Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information."}]}},"nvd":{"publishedDate":"2020-11-05 21:15:00","lastModifiedDate":"2023-11-07 03:20:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:self_service_password_reset:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.0.0","versionEndIncluding":"4.4.0.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:self_service_password_reset:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0.1","versionEndIncluding":"4.5.0.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"25837","Ordinal":"187255","Title":"CVE-2020-25837","CVE":"CVE-2020-25837","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"25837","Ordinal":"1","NoteData":"Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"25837","Ordinal":"2","NoteData":"2020-11-05","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"25837","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}