Vulnerability Description
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified debug function, aka SAP Security Note 2241978.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Hana | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2016/Apr/59
- https://erpscan.io/advisories/erpscan-16-002-sap-hana-log-injection-and-no-size-
- https://erpscan.io/press-center/blog/sap-security-notes-january-2016-review/
- http://seclists.org/fulldisclosure/2016/Apr/59
- https://erpscan.io/advisories/erpscan-16-002-sap-hana-log-injection-and-no-size-
- https://erpscan.io/press-center/blog/sap-security-notes-january-2016-review/
FAQ
What is CVE-2016-1929?
CVE-2016-1929 is a vulnerability with a CVSS score of 9.3 (CRITICAL). The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, relate...
How severe is CVE-2016-1929?
CVE-2016-1929 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-1929?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Hana.