VulnerabilityModified
CVE-2016-6149
SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
MEDIUM 5.5EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/hana sps09
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/138456/SAP-HANA-SPS09-1.00.091.00.1418659308-EXPORT-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Aug/108
- http://seclists.org/fulldisclosure/2016/Aug/97
- http://www.securityfocus.com/bid/92061Third Party Advisory, VDB Entry
- https://www.onapsis.com/blog/analyzing-sap-security-notes-january-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-information-disclosure-exportPermissions Required, Third Party Advisory
- http://packetstormsecurity.com/files/138456/SAP-HANA-SPS09-1.00.091.00.1418659308-EXPORT-Information-Disclosure.html
- http://seclists.org/fulldisclosure/2016/Aug/108
- http://seclists.org/fulldisclosure/2016/Aug/97
- http://www.securityfocus.com/bid/92061Third Party Advisory, VDB Entry
- https://www.onapsis.com/blog/analyzing-sap-security-notes-january-2016Third Party Advisory
- https://www.onapsis.com/research/security-advisories/sap-hana-information-disclosure-exportPermissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.