CVE-2020-7196
Estado: ModificadaMedia (6.5)—
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200, CWE-522
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7196",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "BlueData EPIC Software; HPE Ezmeral Container Platform",
"versions": [
{
"status": "affected",
"version": "4.0 and earlier"
},
{
"status": "affected",
"version": "5.0"
}
]
}
]
}
],
"published": "2020-10-26T16:15:14.097",
"references": [
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04049en_us",
"tags": [
"Vendor Advisory"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04049en_us",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url \"/bdswebui/assignusers/\"."
},
{
"lang": "es",
"value": "HPE BlueData EPIC Software Platform versión 4.0 y HPE Ezmeral Container Platform versión 5.0, usan un método no seguro para manejar contraseñas de Kerberos confidenciales que es susceptible de interceptación y/o recuperación no autorizada. Específicamente, muestran la función kdc_admin_password en el archivo fuente de la URL \"/bdswebui/ assignusers/\""
}
],
"lastModified": "2026-06-17T03:24:29.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:bluedata_epic:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0AA40C4-D6C8-4072-AB92-31036E820F90",
"versionEndIncluding": "4.0"
},
{
"criteria": "cpe:2.3:a:hp:ezmeral_container_platform:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F751C3FE-7A93-41B8-A894-F38F44C8D816"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-alert@hpe.com"
}