CVE-2020-15367: Venki Supravizio Bpm

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

Affected products

  • Venki Supravizio Bpm: version 10.1.2 only

Published 2020-07-07. Last modified 2026-06-17.