First published: Tue May 12 2015(Updated: )
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Sybase Unwired Platform Online Data Proxy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3978 is classified as a high severity vulnerability due to its potential to expose sensitive login information.
To fix CVE-2015-3978, ensure that the latest security patches provided by SAP are applied to the affected systems.
CVE-2015-3978 affects local users of SAP Sybase Unwired Platform Online Data Proxy who can access the DataVault.
CVE-2015-3978 allows local users to obtain sensitive usernames and passwords stored in the DataVault.
As a temporary workaround for CVE-2015-3978, limit local user access to the affected system until a patch is applied.