CVE-2020-25255

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attackers to cause a denial of service (outage of connection-request processing) via a long user ID, which triggers an exception and a large log entry.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
hylandonbase
𝑥
≤ 16.0.2.83
hylandonbase
17.0.0.0 ≤
𝑥
≤ 17.0.2.109
hylandonbase
18.0.0.0 ≤
𝑥
≤ 18.0.0.37
hylandonbase
19.0.0.0 ≤
𝑥
≤ 19.8.16.1000
hylandonbase
20.0.0.0 ≤
𝑥
≤ 20.3.10.1000
𝑥
= Vulnerable software versions