VulnerabilityModified
CVE-2016-3640
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password information via vectors related to passwords in Web Dispatcher trace files, aka SAP Security Note 2148905.
MEDIUM 5.5EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password information via vectors related to passwords in Web Dispatcher trace files, aka SAP Security Note 2148905.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/hana db
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/92068Third Party Advisory, VDB Entry
- https://layersevensecurity.com/wp-content/uploads/2015/10/Layer-Seven-Security_SAP-Security-Notes_August-2015.pdfTechnical Description
- https://www.onapsis.com/blog/analyzing-sap-security-notes-august-2015-editionThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-password-disclosurePermissions Required, Third Party Advisory
- http://www.securityfocus.com/bid/92068Third Party Advisory, VDB Entry
- https://layersevensecurity.com/wp-content/uploads/2015/10/Layer-Seven-Security_SAP-Security-Notes_August-2015.pdfTechnical Description
- https://www.onapsis.com/blog/analyzing-sap-security-notes-august-2015-editionThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-password-disclosurePermissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.