A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://support.broadcom.com/external/content/SecurityAdvisories/0/23239 | vendor advisory |