The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.
References
Link | Resource |
---|---|
http://onapsis.com/research/security-advisories/sap-trex-tns-information-disclosure-nameserver | Permissions Required Third Party Advisory |
http://packetstormsecurity.com/files/138445/SAP-TREX-7.10-Revision-63-NameServer-TNS-Information-Disclosure.html | Third Party Advisory VDB Entry |
http://scn.sap.com/community/security/blog/2015/12/09/sap-security-notes-december-2015--review | Vendor Advisory |
http://seclists.org/fulldisclosure/2016/Aug/93 | Third Party Advisory |
https://layersevensecurity.com/wp-content/uploads/2016/03/Layer-Seven-Security_SAP-Security-Notes_February-2016.pdf | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2016-09-27 15:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-6146
Mitre link : CVE-2016-6146
CVE.ORG link : CVE-2016-6146
JSON object : View
Products Affected
sap
- trex
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor