PT-2019-4301 · Sap · Sap Landscape Management

Published

2019-10-08

·

Updated

2020-02-10

·

CVE-2019-0380

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Landscape Management enterprise edition versions prior to 3.0
Description The issue is related to insufficient protection of registration data, which can lead to information disclosure. Under certain conditions, custom secure parameters' default values can be part of the application logs. This may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 3.0, update to version 3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to application logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00016
CVE-2019-0380

Affected Products

Sap Landscape Management