PT-2024-11672 · Brocade · Brocade Sannav
Published
2024-11-20
·
Updated
2024-11-21
·
CVE-2022-43937
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brocade SANnav versions prior to 2.3.0
Brocade SANnav version 2.2.2 and earlier
Description
The issue concerns a possible information exposure through a log file vulnerability. Sensitive fields are recorded in the debug-enabled logs when debugging is turned on. This could lead to data compromise.
Recommendations
For Brocade SANnav versions prior to 2.3.0, upgrade to version 2.3.0 or later.
For Brocade SANnav version 2.2.2 and earlier, upgrade to a version later than 2.2.2.
As a temporary workaround, consider disabling debug logging until a patch is available.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brocade Sannav