First published: Wed Aug 12 2020(Updated: )
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compromise of the installed Cockpit. This compromise could enable the attacker to view, modify and/or make unavailable any data associated with the Cockpit, leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Sybase Adaptive Server Enterprise | =16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6295 is classified as critical due to the potential exposure of sensitive information.
To fix CVE-2020-6295, ensure that installation log files are not publicly readable and apply the security patches provided by SAP.
CVE-2020-6295 affects SAP Adaptive Server Enterprise version 16.0.
CVE-2020-6295 allows access to encrypted sensitive and confidential information through installation log files.
Yes, CVE-2020-6295 can lead to the compromise of the installed Cockpit, enabling potential further attacks.