CVE-2016-6142

SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:hana:1.00.73.00.389160:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://onapsis.com/research/security-advisories/sap-hana-arbitrary-audit-injection-sql-protocol - Third Party Advisory () http://onapsis.com/research/security-advisories/sap-hana-arbitrary-audit-injection-sql-protocol - Third Party Advisory
References () http://packetstormsecurity.com/files/138441/SAP-HANA-DB-1.00.73.00.389160-SAP-Protocol-Audit-Injection.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/138441/SAP-HANA-DB-1.00.73.00.389160-SAP-Protocol-Audit-Injection.html - Exploit, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2016/Aug/89 - Third Party Advisory () http://seclists.org/fulldisclosure/2016/Aug/89 - Third Party Advisory
References () http://www.securityfocus.com/bid/92566 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92566 - Third Party Advisory, VDB Entry

Information

Published : 2016-09-26 16:59

Updated : 2024-11-21 02:55


NVD link : CVE-2016-6142

Mitre link : CVE-2016-6142

CVE.ORG link : CVE-2016-6142


JSON object : View

Products Affected

sap

  • hana