PT-2020-5971 · Sap · Sap Adaptive Server Enterprise
Published
2020-08-11
·
Updated
2021-07-21
·
CVE-2020-6295
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Adaptive Server Enterprise version 16.0
Description
The issue allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files, leading to a compromise of the installed Cockpit. This could enable the attacker to view, modify, and/or make unavailable any data associated with the Cockpit, resulting in information disclosure. The vulnerability is related to the lack of protection for service data in the Cockpit component of the Adaptive Server Enterprise database.
Recommendations
For SAP Adaptive Server Enterprise version 16.0, restrict access to the installation log files to prevent publicly readable access and consider additional security measures to protect the Cockpit component.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Adaptive Server Enterprise