A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2589129 | permissions required |
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ | vendor advisory |