Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 | vendor advisory |
https://launchpad.support.sap.com/#/notes/2828682 | permissions required |