PT-2020-20625 · Subex · Subex Roc Partner Settlement

Published

2020-04-14

·

Updated

2024-08-04

·

CVE-2020-9384

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Subex ROC Partner Settlement version 10.5
Description An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature allows remote authenticated users to achieve account takeover via manipulation of POST parameters. This issue may only affect a testing version of the application.
Recommendations For Subex ROC Partner Settlement version 10.5, consider restricting access to the Change Password feature until a fix is available. As a temporary workaround, avoid using the vulnerable Change Password feature to minimize the risk of account takeover. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Weakness Enumeration

Related Identifiers

CVE-2020-9384

Affected Products

Subex Roc Partner Settlement