{ "schema_version": "1.4.0", "id": "GHSA-mx3q-x87f-8pxm", "modified": "2022-05-24T17:34:08Z", "published": "2022-05-24T17:34:08Z", "aliases": [ "CVE-2020-7962" ], "details": "An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7962" }, { "type": "WEB", "url": "https://cxsecurity.com/issue/WLB-2020050185" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-11-13T19:15:00Z" } }