CVE Vulnerabilities

CVE-2019-0380

Insertion of Sensitive Information into Log File

Published: Oct 08, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Landscape_management Sap 3.0 (including) 3.0 (including)

Potential Mitigations

References