CVE-2024-29968: SQL Table names, column names, and SQL queries are collected in DR standby Supportsave
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29968?
CVE-2024-29968 has a medium severity rating due to its potential to disclose sensitive information.
What are the affected versions of Brocade SANnav for CVE-2024-29968?
Brocade SANnav versions 2.3.1 and 2.3.0a and earlier are affected by CVE-2024-29968.
How do I fix CVE-2024-29968?
To fix CVE-2024-29968, update Brocade SANnav to version 2.3.1 or later.
What type of vulnerability is CVE-2024-29968?
CVE-2024-29968 is categorized as an information disclosure vulnerability.
How does CVE-2024-29968 affect Brocade SANnav in disaster recovery mode?
In disaster recovery mode, CVE-2024-29968 allows the collection of SQL table names, column names, and queries, which could lead to sensitive data exposure.