CVE-2016-6150

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified other impact via unknown vectors, aka SAP Security Note 2233550.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:hana:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/138453/SAP-HANA-DB-Encryption-Issue.html - () http://packetstormsecurity.com/files/138453/SAP-HANA-DB-Encryption-Issue.html -
References () http://seclists.org/fulldisclosure/2016/Aug/96 - () http://seclists.org/fulldisclosure/2016/Aug/96 -
References () http://www.securityfocus.com/bid/92064 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92064 - Third Party Advisory, VDB Entry
References () https://layersevensecurity.com/wp-content/uploads/2016/02/Layer-Seven-Security_SAP-Security-Notes_January-2016.pdf - Technical Description, Third Party Advisory () https://layersevensecurity.com/wp-content/uploads/2016/02/Layer-Seven-Security_SAP-Security-Notes_January-2016.pdf - Technical Description, Third Party Advisory
References () https://www.onapsis.com/research/security-advisories/sap-hana-potential-wrong-encryption - Permissions Required, Third Party Advisory () https://www.onapsis.com/research/security-advisories/sap-hana-potential-wrong-encryption - Permissions Required, Third Party Advisory

Information

Published : 2016-08-05 14:59

Updated : 2024-11-21 02:55


NVD link : CVE-2016-6150

Mitre link : CVE-2016-6150

CVE.ORG link : CVE-2016-6150


JSON object : View

Products Affected

sap

  • hana
CWE
CWE-284

Improper Access Control