CVE-2015-7993
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related to "HTTP Login," aka SAP Security Note 2197397.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related to "HTTP Login," aka SAP Security Note 2197397.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.72% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sap/hana
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/134286/SAP-HANA-HTTP-Login-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2015/Nov/39
- https://www.onapsis.com/blog/analyzing-sap-security-notes-september-2015
- https://www.onapsis.com/research/security-advisories/SAP_HANA_Remote_Code_Execution_HTTP_based
- http://packetstormsecurity.com/files/134286/SAP-HANA-HTTP-Login-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2015/Nov/39
- https://www.onapsis.com/blog/analyzing-sap-security-notes-september-2015
- https://www.onapsis.com/research/security-advisories/SAP_HANA_Remote_Code_Execution_HTTP_based
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.