SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified other impact via a TrexNet packet to the (1) fcopydir, (2) fmkdir, (3) frmdir, (4) getenv, (5) dumpenv, (6) fcopy, (7) fput, (8) fdel, (9) fmove, (10) fget, (11) fappend, (12) fdir, (13) getTraces, (14) kill, (15) pexec, (16) stop, or (17) pythonexec method, aka SAP Security Note 2165583.
References
Configurations
History
21 Nov 2024, 02:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/134281/SAP-HANA-TrexNet-Command-Execution.html - | |
References | () http://seclists.org/fulldisclosure/2015/Nov/36 - | |
References | () https://www.onapsis.com/blog/analyzing-sap-security-notes-august-2015-edition - |
Information
Published : 2015-11-10 17:59
Updated : 2024-11-21 02:37
NVD link : CVE-2015-7828
Mitre link : CVE-2015-7828
CVE.ORG link : CVE-2015-7828
JSON object : View
Products Affected
sap
- hana
CWE
CWE-20
Improper Input Validation