First published: Mon Nov 29 2021(Updated: )
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.
Credit: cve@mitre.org ub3rsick
Affected Software | Affected Version | How to fix |
---|---|---|
Wipro Holmes | =20.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38283 is high, with a CVSS score of 7.5.
CVE-2021-38283 allows remote attackers to read application log files containing sensitive information in Wipro Holmes Orchestrator 20.4.1.
Attackers can exploit CVE-2021-38283 by accessing the predictable /log URI and reading the application log files.
Wipro Holmes Orchestrator version 20.4.1 is affected by CVE-2021-38283.
Information about patches or fixes for CVE-2021-38283 can be found on the official Wipro website.