Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14839

Опубликовано: 31 мая 2021
Источник: redhat
CVSS3: 5.4

Описание

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

A flaw was found in Business Central. When logging into the Business-central console, the HTTP request discloses sensitive information such as the username and password. This issue occurs when intercepted with tools like Burp Suite, etc.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7Business-centralAffected
Red Hat Process Automation 7Business-centralAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1748178Business-central: HTTP Request interception disclose sensitive information like username and password

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

CVSS3: 7.5
github
почти 4 года назад

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

5.4 Medium

CVSS3