SANnav 的作业调度组件中存在信息泄露漏洞,该漏洞允许敏感凭据以明文形式写入应用程序日志。当执行调度的支持保存作业或相关运维任务时,包括外部服务器密码和归档保护密钥在内的敏感参数会被记录在日志中,且未进行适当的脱敏处理。具有应用程序日志或支持包访问权限的本地用户或已认证用户即可查看这些明文凭据,可能导致对远程备份目标或受保护归档文件的未授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82372 | 8.5 HIGH | Improper handling of sensitive data during IPsec policy creation and modification in Broca |
| CVE-2026-82371 | 8.5 HIGH | Plaintext exposure of sensitive authentication data in SANnav discovery service log files |
| CVE-2026-14443 | 8.4 HIGH | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3 |
| CVE-2026-14441 | 6.9 MEDIUM | Logic flaw in SANnav Java cache key handling object comparison handling |
No comments yet