Vulnerability Description
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Hana | 1.00.73.00.389160 |
References
- http://onapsis.com/research/security-advisories/sap-hana-arbitrary-audit-injectiThird Party Advisory
- http://packetstormsecurity.com/files/138441/SAP-HANA-DB-1.00.73.00.389160-SAP-PrExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Aug/89Third Party Advisory
- http://www.securityfocus.com/bid/92566Third Party AdvisoryVDB Entry
- http://onapsis.com/research/security-advisories/sap-hana-arbitrary-audit-injectiThird Party Advisory
- http://packetstormsecurity.com/files/138441/SAP-HANA-DB-1.00.73.00.389160-SAP-PrExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Aug/89Third Party Advisory
- http://www.securityfocus.com/bid/92566Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-6142?
CVE-2016-6142 is a vulnerability with a CVSS score of 7.5 (HIGH). SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
How severe is CVE-2016-6142?
CVE-2016-6142 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6142?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Hana.