PT-2020-19091 · Sap · Sap Adaptive Server Enterprise

Published

2020-11-30

·

Updated

2021-07-21

·

CVE-2020-6317

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Adaptive Server Enterprise versions 15.7, 16.0
Description The issue allows an attacker with regular user credentials and local access to an ASE cockpit installation to access sensitive information in the installation log files. Although this information is sensitive, it has limited utility and cannot be used to further access, modify, or render unavailable any other information in the cockpit or system.
Recommendations For SAP Adaptive Server Enterprise versions 15.7 and 16.0, consider restricting access to the installation log files as a temporary workaround to minimize the risk of sensitive information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6317

Affected Products

Sap Adaptive Server Enterprise