Vulnerability Name: | CVE-2016-6150 (CCN-115948) | ||||||||||||
Assigned: | 2016-01-01 | ||||||||||||
Published: | 2016-01-01 | ||||||||||||
Updated: | 2016-11-28 | ||||||||||||
Summary: | The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified other impact via unknown vectors, aka SAP Security Note 2233550. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-284 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-6150 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/138453/SAP-HANA-DB-Encryption-Issue.html Source: CCN Type: Full-Disclosure Mailing List, Fri, 19 Aug 2016 12:24:32 -0300 Onapsis Security Advisory ONAPSIS-2016-040: SAP HANA potential wrong encryption Source: FULLDISC Type: UNKNOWN 20160819 Onapsis Security Advisory ONAPSIS-2016-040: SAP HANA potential wrong encryption Source: BID Type: Third Party Advisory, VDB Entry 92064 Source: CCN Type: BID-92064 SAP HANA CVE-2016-6150 Access Bypass Vulnerability Source: XF Type: UNKNOWN sap-hana-cve20166150-sec-bypass(115948) Source: CCN Type: Layer Seven Security Web site SAP Security Notes Source: MISC Type: Technical Description, Third Party Advisory https://layersevensecurity.com/wp-content/uploads/2016/02/Layer-Seven-Security_SAP-Security-Notes_January-2016.pdf Source: CCN Type: SAP Web site SAP Security Notes 2233550 Source: MISC Type: Permissions Required, Third Party Advisory https://www.onapsis.com/research/security-advisories/sap-hana-potential-wrong-encryption | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |