High severity8.8NVD Advisory· Published Apr 14, 2020· Updated Jun 17, 2026
CVE-2020-9384
CVE-2020-9384
Description
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vulnerability may only affect a testing version of the application
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Subex/ROC Partner Settlementdescription
- Range: = 10.5
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/157197/Subex-ROC-Partner-Settlement-10.5-Insecure-Direct-Object-Reference.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.subex.com/partner-settlement/nvdVendor Advisory
News mentions
0No linked articles in our index yet.