VulnerabilityModified
CVE-2015-7986
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.
HIGH 7.5EPSS 6.24%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 6.24% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- sap/hana
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/135416/SAP-HANA-hdbindexserver-Memory-Corruption.htmlExploit
- http://scn.sap.com/community/security/blog/2015/10/14/sap-security-notes-october-2015--reviewVendor Advisory
- http://seclists.org/fulldisclosure/2016/Jan/94
- http://www.securityfocus.com/archive/1/537376/100/0/threaded
- https://erpscan.io/advisories/erpscan-15-024-sap-hana-hdbindexserver-memory-corruption/
- https://www.exploit-db.com/exploits/39382/
- http://packetstormsecurity.com/files/135416/SAP-HANA-hdbindexserver-Memory-Corruption.htmlExploit
- http://scn.sap.com/community/security/blog/2015/10/14/sap-security-notes-october-2015--reviewVendor Advisory
- http://seclists.org/fulldisclosure/2016/Jan/94
- http://www.securityfocus.com/archive/1/537376/100/0/threaded
- https://erpscan.io/advisories/erpscan-15-024-sap-hana-hdbindexserver-memory-corruption/
- https://www.exploit-db.com/exploits/39382/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.