First published: Tue Sep 03 2019(Updated: )
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Business-central | <=7.48.0 | |
Redhat Descision Manager | =7.0 | |
Redhat Process Automation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-14839.
The severity of CVE-2019-14839 is high with a score of 7.5.
Redhat Business-central, Redhat Descision Manager, and Redhat Process Automation versions up to 7.0 are affected by CVE-2019-14839.
CVE-2019-14839 is a vulnerability in Business-central console that exposes sensitive information like username and password when intercepted using tools like burp suite.
To mitigate CVE-2019-14839, it is recommended to update Redhat Business-central, Redhat Descision Manager, and Redhat Process Automation to a version that fixes the vulnerability.