CVE-2024-0912

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
Configurations

Configuration 1 (hide)

cpe:2.3:h:johnsoncontrols:software_house_c-cure_9000_siteserver:3.00.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-06 00:15

Updated : 2024-07-18 18:56


NVD link : CVE-2024-0912

Mitre link : CVE-2024-0912

CVE.ORG link : CVE-2024-0912


JSON object : View

Products Affected

johnsoncontrols

  • software_house_c-cure_9000_siteserver
CWE
CWE-532

Insertion of Sensitive Information into Log File