PT-2026-3556 · Widen · Verve Asset Manager
CVE-2025-14376
·
Publicado
2026-01-20
·
Atualizado
2026-01-20
CVSS v4.0
8.6
Alta
| Vetor | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Verve Asset Manager versions prior to 1.36
Description
A security issue exists in the legacy ADI server component of Verve Asset Manager. The issue involves the storage of plaintext secrets in environment variables on the ADI server. This component was retired and became optional with the 1.36 release in 2024. The vulnerable component does not involve any API endpoints or specific parameters.
Recommendations
Update to version 1.36 or later to eliminate the use of the legacy ADI server component.
Correção
Insecure Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Verve Asset Manager