VulnerabilityModified
CVE-2019-0380
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
MEDIUM 4.9EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- sap/landscape management
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2828682Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2828682Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.