Executive brief
Avantra, an operations management platform for SAP landscapes, contains a vulnerability where sensitive information is inadvertently recorded in system log files. This could allow unauthorized individuals with access to the logs to view protected data, potentially leading to further system compromise or data exposure. The issue affects Avantra installations on both Linux and Windows environments.
Technical details
A vulnerability classified as CWE-532 (Insertion of Sensitive Information into Log File) exists in syslink software AG Avantra prior to version 25.3.0. The application records sensitive data into logs, which can be exploited to gain unauthorized access to credentials or configuration details. While one CVSS vector suggests high privileges are required, the NVD-provided vector indicates the vulnerability may be reachable over the network without authentication. This exposure can lead to a 'Resource Leak Exposure' scenario on both Linux and Windows platforms. Users are advised to upgrade to version 25.3.0 or later to mitigate this risk.
Affected products
- syslink software AG Avantra before 25.3.0
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory