{"api_version":"1","generated_at":"2026-07-23T12:07:13+00:00","cve":"CVE-2020-9518","urls":{"html":"https://cve.report/CVE-2020-9518","api":"https://cve.report/api/cve/CVE-2020-9518.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9518","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9518"},"summary":{"title":"CVE-2020-9518","description":"Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2020-03-16 14:15:00","updated_at":"2023-11-07 03:26:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://softwaresupport.softwaregrp.com/doc/KM03607792","name":"https://softwaresupport.softwaregrp.com/doc/KM03607792","refsource":"","tags":[],"title":"MySupport - Micro Focus Software Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9518","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9518","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9518","vulnerable":"1","versionEndIncluding":"9.62","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microfocus","cpe5":"service_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-9518","ASSIGNER":"security@microfocus.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Micro Focus International","product":{"product_data":[{"product_name":"Service Manager (Web Tier).","version":{"version_data":[{"version_value":"9.50, 9.51, 9.52, 9.60, 9.61, 9.62"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Login filter can access configuration files"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://softwaresupport.softwaregrp.com/doc/KM03607792","url":"https://softwaresupport.softwaregrp.com/doc/KM03607792"}]},"description":{"description_data":[{"lang":"eng","value":"Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data."}]}},"nvd":{"publishedDate":"2020-03-16 14:15:00","lastModifiedDate":"2023-11-07 03:26:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:microfocus:service_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"9.50","versionEndIncluding":"9.62","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9518","Ordinal":"169909","Title":"CVE-2020-9518","CVE":"CVE-2020-9518","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9518","Ordinal":"1","NoteData":"Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9518","Ordinal":"2","NoteData":"2020-03-16","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9518","Ordinal":"3","NoteData":"2020-03-16","Type":"Other","Title":"Modified"}]}}}