CVE-2020-15367: Venki Supravizio Bpm
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
Affected products
- Venki Supravizio Bpm: version 10.1.2 only
Published 2020-07-07. Last modified 2026-06-17.