#VU100246 Unprotected storage of credentials in SAP NetWeaver AS JAVA - CVE-2024-47588
Published: November 12, 2024
SAP NetWeaver AS JAVA
SAP
Description
The vulnerability allows a local user to gain access to other users' credentials.
The vulnerability exists due to the Software Update Manager 1.1 stored credentials in plain text in a log file on the system when a software upgrade encounters errors. A local user can view contents of the configuration file and gain access to passwords for 3rd party integration.