3.5
CVE-2020-6317
- EPSS 0.07%
- Veröffentlicht 30.11.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:29
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and cannot be used to further access, modify or render unavailable any other information in the cockpit or system. This affects SAP Adaptive Server Enterprise, Versions - 15.7, 16.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Adaptive Server Enterprise Version15.7
SAP ≫ Adaptive Server Enterprise Version16.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.188 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 2.7 | 5.1 | 2.9 |
AV:A/AC:L/Au:S/C:P/I:N/A:N
|
cna@sap.com | 2.6 | 1.2 | 1.4 |
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.