SB2019122639 - Missing Encryption of Sensitive Data in elfutils (Alpine package)
Published: December 26, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Encryption of Sensitive Data (CVE-ID: CVE-2019-16062)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
Remediation
Install update from vendor's website.