PT-2026-3556 · Widen · Verve Asset Manager

CVE-2025-14376

·

Publicado

2026-01-20

·

Atualizado

2026-01-20

CVSS v4.0

8.6

Alta

VetorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Verve Asset Manager versions prior to 1.36
Description A security issue exists in the legacy ADI server component of Verve Asset Manager. The issue involves the storage of plaintext secrets in environment variables on the ADI server. This component was retired and became optional with the 1.36 release in 2024. The vulnerable component does not involve any API endpoints or specific parameters.
Recommendations Update to version 1.36 or later to eliminate the use of the legacy ADI server component.

Correção

Insecure Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14376

Produtos afetados

Verve Asset Manager