PT-2018-15505 · Sap · Sap Hana Extended Application Services

CVE-2018-2372

·

Publicado

2018-02-14

·

Atualizado

2023-12-21

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP HANA Extended Application Services version 1.0
Description A plain keystore password is written to a system log file, which could endanger the confidentiality of SSL communication.
Recommendations For SAP HANA Extended Application Services version 1.0, consider restricting access to system log files to minimize the risk of exploitation. As a temporary workaround, review and securely configure logging settings to prevent sensitive information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-2372

Produtos afetados

Sap Hana Extended Application Services