CVE Vulnerabilities

CVE-2022-39821

Insertion of Sensitive Information into Log File

Published: Sep 13, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
1350_optical_management_system Nokia 14.2 (including) 14.2 (including)

Potential Mitigations

References