CVE-2016-6145
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as…
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/hana db
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/138444/SAP-HANA-DB-1.00.091.00.1418659308-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Aug/92Third Party Advisory
- http://www.securityfocus.com/bid/92346
- https://www.onapsis.com/blog/onapsis-publishes-15-advisories-sap-hana-and-building-componentsThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-user-information-disclosurePermissions Required
- http://packetstormsecurity.com/files/138444/SAP-HANA-DB-1.00.091.00.1418659308-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Aug/92Third Party Advisory
- http://www.securityfocus.com/bid/92346
- https://www.onapsis.com/blog/onapsis-publishes-15-advisories-sap-hana-and-building-componentsThird Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-user-information-disclosurePermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.