AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-5425

HIGH · CVSS 7.9 EPSS 0.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-10-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.9. It affects VMware, VMWare.

CVE
CVE-2020-5425
Severity
HIGH
CVSS
7.9
EPSS
0.73%
VMware VMWare

Original NVD Description

Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two different identity providers, one can acquire the token of the other and thus operate with their permissions. Note: Foundation may be vulnerable only if: 1) The system zone is set up to use a SAML identity provider 2) There are internal users that have the same username as users in the external SAML provider 3) Those duplicate-named users have the scope to access the SSO operator dashboard 4) The vulnerability doesn't appear with LDAP because of chained authentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)