SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
References
Configurations
History
21 Nov 2024, 02:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/138456/SAP-HANA-SPS09-1.00.091.00.1418659308-EXPORT-Information-Disclosure.html - | |
References | () http://seclists.org/fulldisclosure/2016/Aug/108 - | |
References | () http://seclists.org/fulldisclosure/2016/Aug/97 - | |
References | () http://www.securityfocus.com/bid/92061 - Third Party Advisory, VDB Entry | |
References | () https://www.onapsis.com/blog/analyzing-sap-security-notes-january-2016 - Third Party Advisory | |
References | () https://www.onapsis.com/research/security-advisories/sap-hana-information-disclosure-export - Permissions Required, Third Party Advisory |
Information
Published : 2016-08-05 14:59
Updated : 2024-11-21 02:55
NVD link : CVE-2016-6149
Mitre link : CVE-2016-6149
CVE.ORG link : CVE-2016-6149
JSON object : View
Products Affected
sap
- hana_sps09
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor