← Back

CVE-2022-4311

nvd nist
Published: Dec 12, 2022Modified: Jul 9, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

Affected (1)

Products: Arcinfo: Pcvue
1 product
Pcvue
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 15 to 15.2.2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory

Timeline

No history available yet.