CVE-2020-6317

LOW

SAP ASE <16.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and cannot be used to further access, modify or render unavailable any other information in the cockpit or system. This affects SAP Adaptive Server Enterprise, Versions - 15.7, 16.0.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2953203

Scores

CVSS v3 3.5
EPSS 0.0007
EPSS Percentile 21.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
sap/adaptive_server_enterprise 15.7
sap/adaptive_server_enterprise 16.0
Published Nov 30, 2020
Tracked Since Feb 18, 2026