« Volver al listado

CVE-2020-25258

Estado: ModificadaCrítica (9.8)—

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses ASP.NET BinaryFormatter.Deserialize in a manner that allows attackers to transmit and execute bytecode in SOAP messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-25258",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-11T03:15:13.020",
  "references": [
    {
      "url": "https://seclists.org/fulldisclosure/2020/Sep/22",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://seclists.org/fulldisclosure/2020/Sep/22",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses ASP.NET BinaryFormatter.Deserialize in a manner that allows attackers to transmit and execute bytecode in SOAP messages."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en Hyland OnBase versión 16.0.2.83 e inferior, versión 17.0.2.109 e inferior, versión 18.0.0.37 e inferior, versión 19.8.16.1000 e inferior y versión 20.3.10.1000 e inferior. Utiliza ASP.NET BinaryFormatter.Deserializar de manera que permite a los atacantes transmitir y ejecutar bytecode en los mensajes SOAP"
    }
  ],
  "lastModified": "2026-06-17T03:06:40.807",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8676658E-9F96-4213-9062-119274A085A4",
              "versionEndIncluding": "16.0.2.83"
            },
            {
              "criteria": "cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46DE98EF-38B4-4C32-8FF1-54D1733771AC",
              "versionEndIncluding": "17.0.2.109",
              "versionStartIncluding": "17.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFEE664C-014B-4B42-8DA2-86617D8E279E",
              "versionEndIncluding": "18.0.0.37",
              "versionStartIncluding": "18.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78E72BFC-F30C-45FF-9253-2CF1FF633B82",
              "versionEndIncluding": "19.8.16.1000",
              "versionStartIncluding": "19.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:hyland:onbase:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "966A05D7-1D0A-4618-9DFC-8F1A062D3DC6",
              "versionEndIncluding": "20.3.10.1000",
              "versionStartIncluding": "20.0.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}