CVE-2020-7196
26.10.2020, 16:15
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".Enginsight
Vendor | Product | Version |
---|---|---|
hp | bluedata_epic | 𝑥 ≤ 4.0 |
hp | ezmeral_container_platform | 5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration