CVE-2020-25837: Micro Focus Self Service Password Reset

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

Affected products

  • Micro Focus Self Service Password Reset: from 4.4.0.0, up to and including 4.4.0.6; from 4.5.0.1, up to and including 4.5.0.2

Published 2020-11-05. Last modified 2026-06-17.