CVE-2020-12712

A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sos-berlin:jobscheduler:*:*:*:*:*:*:*:*
cpe:2.3:a:sos-berlin:jobscheduler:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:00

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/158112/SOS-JobScheduler-1.13.3-Stored-Password-Decryption.html - Third Party Advisory () http://packetstormsecurity.com/files/158112/SOS-JobScheduler-1.13.3-Stored-Password-Decryption.html - Third Party Advisory
References () https://change.sos-berlin.com/browse/JOE-290 - Vendor Advisory () https://change.sos-berlin.com/browse/JOE-290 - Vendor Advisory
References () https://kb.sos-berlin.com/display/PKB/Vulnerability+Release+1.13.4 - Release Notes, Vendor Advisory () https://kb.sos-berlin.com/display/PKB/Vulnerability+Release+1.13.4 - Release Notes, Vendor Advisory
References () https://www.sos-berlin.com/en/news - Vendor Advisory () https://www.sos-berlin.com/en/news - Vendor Advisory

Information

Published : 2020-06-11 14:15

Updated : 2024-11-21 05:00


NVD link : CVE-2020-12712

Mitre link : CVE-2020-12712

CVE.ORG link : CVE-2020-12712


JSON object : View

Products Affected

sos-berlin

  • jobscheduler
CWE
CWE-330

Use of Insufficiently Random Values