Vulnerability Description
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and cannot be used to further access, modify or render unavailable any other information in the cockpit or system. This affects SAP Adaptive Server Enterprise, Versions - 15.7, 16.0.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Adaptive Server Enterprise | 15.7 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2953203Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2953203Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700Vendor Advisory
FAQ
What is CVE-2020-6317?
CVE-2020-6317 is a vulnerability with a CVSS score of 3.5 (LOW). In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This info...
How severe is CVE-2020-6317?
CVE-2020-6317 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6317?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Adaptive Server Enterprise.