Risk | Medium |
Patch available | NO |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-35992 |
CWE-ID | CWE-522 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Prologue Other software / Other software solutions |
Vendor | Fiserv |
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU66799
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-35992
CWE-ID:
CWE-522 - Insufficiently Protected Credentials
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the failure to protect the database password. A remote user can gain unauthorized access to sensitive information on the system.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsPrologue: 2020-12-16
http://github.com/micahvandeusen/PrologueDecrypt
http://www.fiserv.com
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?