CVE Vulnerabilities

CVE-2022-39821

Insertion of Sensitive Information into Log File

Published: Sep 13, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
1350_optical_management_systemNokia14.2 (including)14.2 (including)

Potential Mitigations

References