Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the application enables the logging mechanism by generating the log file, which can be downloaded.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-10-03T13:24:44.830Z
Updated: 2024-09-19T19:47:16.780Z
Reserved: 2023-06-21T11:12:46.069Z
Link: CVE-2023-3349
Vulnrichment
Updated: 2024-08-02T06:55:03.160Z
NVD
Status : Modified
Published: 2023-10-03T14:15:10.853
Modified: 2024-11-21T08:17:04.560
Link: CVE-2023-3349
Redhat
No data.