Description
Oracle SQLNet and/or listener log files are publicly accessible. The SQLNet and Listener log files provide audit data useful to the discovery of suspicious behavior. The log files may contain usernames and passwords in clear text as well as other information that could aid a malicious user with unauthorized access attempts to the database. Generation and protection of these files helps support security monitoring efforts.
Remediation
Restrict access to the listener and sqlnet log files.
References
Related Vulnerabilities
WordPress Plugin Product Subtitle For WooCommerce Arbitrary File Disclosure (4.1)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.29)
Atlassian JIRA Servicedesk misconfiguration
WebPageTest Unauthorized Access Vulnerability
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-46158)