Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-955r-gv79-5833

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

EPSS

Процентиль: 50%
0.00271
Низкий

8.4 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.6
nvd
почти 8 лет назад

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

EPSS

Процентиль: 50%
0.00271
Низкий

8.4 High

CVSS3

Дефекты

CWE-200