6.5
CVSSv2

CVE-2020-9384

Published: 14/04/2020 Updated: 11/04/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vulnerability may only affect a testing version of the application

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

subex roc partner settlement 10.5

Exploits

Subex ROC Partner Settlement version 105 suffers from an insecure direct object reference vulnerability in the change password function that can allow for account takeover ...