CVE-2020-15367
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
- Affected products
- Venki Supravizio Bpm
- Venki Supravizio Bpm
- = 10.1.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 2.0% (79th percentile)
- Weakness
- CWE-307
- NVD status
- Modified
- Published
- 2020-07-07
CVE-2020-15367 at NVD
1 known exploit for CVE-2020-15367
Proof-of-concept code and exploit modules indexed by Sploitus