PT-2020-19091 · Sap · Sap Adaptive Server Enterprise
Published
2020-11-30
·
Updated
2021-07-21
·
CVE-2020-6317
CVSS v3.1
3.5
Low
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Adaptive Server Enterprise versions 15.7, 16.0
Description
The issue allows an attacker with regular user credentials and local access to an ASE cockpit installation to access sensitive information in the installation log files. Although this information is sensitive, it has limited utility and cannot be used to further access, modify, or render unavailable any other information in the cockpit or system.
Recommendations
For SAP Adaptive Server Enterprise versions 15.7 and 16.0, consider restricting access to the installation log files as a temporary workaround to minimize the risk of sensitive information disclosure.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Adaptive Server Enterprise