CVE-2025-58130
BaseFortify
Publication date: 2025-12-12
Last updated on: 2025-12-18
Assigner: Apache Software Foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | fineract | to 1.12.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Apache Fineract involves insufficiently protected credentials, meaning that the credentials used by the system are not adequately secured, potentially allowing unauthorized access.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized access to the system due to poorly protected credentials, which may lead to data breaches or compromise of sensitive information.
What immediate steps should I take to mitigate this vulnerability?
Upgrade Apache Fineract to version 1.12.1 or later, preferably to the latest release 1.13.0, as the vulnerability is fixed in these versions.