CVE-2019-14886
published 2020-03-05CVE-2019-14886: A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.29%
21.0th percentile
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | business-central | — | — |
| redhat | decision_manager | — | — |
| redhat | process_automation_manager | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.6MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Business-central: Encrypted password shown under Object id 7 of errai_security_context
vendor_redhat·2019-09-23·CVSS 6.5
CVE-2019-14886 [MEDIUM] CWE-312 Business-central: Encrypted password shown under Object id 7 of errai_security_context
Business-central: Encrypted password shown under Object id 7 of errai_security_context
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
A vulnerability was found in business-central where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
GHSA
GHSA-5prq-gjqm-96r8: A vulnerability was found in business-central, as shipped in rhdm-7
ghsa_unreviewed·2022-05-24
CVE-2019-14886 [MEDIUM] CWE-312 GHSA-5prq-gjqm-96r8: A vulnerability was found in business-central, as shipped in rhdm-7
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14886https://groups.google.com/forum/?utm_medium=email&utm_source=footer#%21msg/jbpm-usage/74pSuwfGKRU/0oXpmRScBQAJhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14886https://groups.google.com/forum/?utm_medium=email&utm_source=footer#%21msg/jbpm-usage/74pSuwfGKRU/0oXpmRScBQAJ
2020-03-05
Published