Information exposure on IBERMATICA RPS
CVE-2023-3349
8.2HIGH
What is CVE-2023-3349?
An information exposure vulnerability has been identified in IBERMATICA RPS 2019, enabling unauthenticated users to gain access to sensitive information. By navigating to the URL /RPS2019Service/status.html, attackers can exploit the application's logging functionality, which creates a log file available for download. This log file may contain sensitive data, including usernames, IP addresses, and SQL queries, posing a significant risk to the confidentiality and integrity of the application.
Affected Version(s)
IBERMATICA RPS 2019 RPS 2019
