CVE-2019-14839: Infoleak
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-14839.
What is the severity of CVE-2019-14839?
The severity of CVE-2019-14839 is high with a score of 7.5.
Which software is affected by CVE-2019-14839?
Redhat Business-central, Redhat Descision Manager, and Redhat Process Automation versions up to 7.0 are affected by CVE-2019-14839.
What is the description of CVE-2019-14839?
CVE-2019-14839 is a vulnerability in Business-central console that exposes sensitive information like username and password when intercepted using tools like burp suite.
How can I mitigate CVE-2019-14839?
To mitigate CVE-2019-14839, it is recommended to update Redhat Business-central, Redhat Descision Manager, and Redhat Process Automation to a version that fixes the vulnerability.