First published: Tue Oct 08 2019(Updated: )
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Landscape Management | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0380 is a vulnerability in SAP Landscape Management enterprise edition before version 3.0 that allows custom secure parameters' default values to be part of the application logs leading to Information Disclosure.
The severity of CVE-2019-0380 is medium with a severity value of 4.9.
CVE-2019-0380 affects SAP Landscape Management enterprise edition before version 3.0 by allowing custom secure parameters' default values to be part of the application logs, leading to Information Disclosure.
To fix CVE-2019-0380, upgrade to SAP Landscape Management enterprise edition version 3.0 or higher.
More information about CVE-2019-0380 can be found at the following references: [link 1], [link 2].