SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-27374 | SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-04T08:55:22.154Z
Reserved: 2020-01-08T00:00:00
Link: CVE-2020-6224
No data.
Status : Modified
Published: 2020-04-14T19:15:17.530
Modified: 2024-11-21T05:35:20.047
Link: CVE-2020-6224
No data.
OpenCVE Enrichment
No data.
EUVD