CVE-2015-3978: Infoleak
Published May 12, 2015
·Updated
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.
Affected Software
1 affected component
SAP Sybase Unwired Platform Online Data Proxy
Event History
May 12, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3978?
CVE-2015-3978 is classified as a high severity vulnerability due to its potential to expose sensitive login information.
2
How do I fix CVE-2015-3978?
To fix CVE-2015-3978, ensure that the latest security patches provided by SAP are applied to the affected systems.
3
Who is affected by CVE-2015-3978?
CVE-2015-3978 affects local users of SAP Sybase Unwired Platform Online Data Proxy who can access the DataVault.
4
What type of information can be compromised by CVE-2015-3978?
CVE-2015-3978 allows local users to obtain sensitive usernames and passwords stored in the DataVault.
5
Is there a workaround for CVE-2015-3978?
As a temporary workaround for CVE-2015-3978, limit local user access to the affected system until a patch is applied.