An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.
History

Tue, 04 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom brocade Sannav
CPEs cpe:2.3:a:broadcom:brocade_sannav:*:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom brocade Sannav

Thu, 19 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 18 Sep 2024 22:45:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents. An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.
Weaknesses CWE-922

cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2024-09-18T22:32:12.764Z

Reserved: 2024-03-22T05:32:26.687Z

Link: CVE-2024-29968

cve-icon Vulnrichment

Updated: 2024-08-02T01:17:58.610Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-19T06:15:06.497

Modified: 2025-02-04T15:41:56.900

Link: CVE-2024-29968

cve-icon Redhat

No data.