CVE-2020-6317

In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and cannot be used to further access, modify or render unavailable any other information in the cockpit or system. This affects SAP Adaptive Server Enterprise, Versions - 15.7, 16.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:adaptive_server_enterprise:15.7:*:*:*:*:*:*:*
cpe:2.3:a:sap:adaptive_server_enterprise:16.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:35

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2953203 - Permissions Required () https://launchpad.support.sap.com/#/notes/2953203 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 - Vendor Advisory

Information

Published : 2020-11-30 19:15

Updated : 2024-11-21 05:35


NVD link : CVE-2020-6317

Mitre link : CVE-2020-6317

CVE.ORG link : CVE-2020-6317


JSON object : View

Products Affected

sap

  • adaptive_server_enterprise
CWE
CWE-532

Insertion of Sensitive Information into Log File