An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This
could allow a user with access to the log files to discover connection strings of data sources configured for the
DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users
unauthorized access to the underlying data sources.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-12-12T17:08:30.847Z
Updated: 2024-08-03T01:34:50.134Z
Reserved: 2022-12-06T19:08:45.932Z
Link: CVE-2022-4311
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-12T18:15:13.300
Modified: 2024-11-21T07:35:00.413
Link: CVE-2022-4311
Redhat
No data.