CVE-2016-6143
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sap | hana | 1.00.73.00.389160 | |
References
- http://www.securityfocus.com/bid/92062
- https://layersevensecurity.com/wp-content/uploads/2015/11/Layer-Seven-Security_SAP-Security-Notes_October-2015.pdf
- https://www.onapsis.com/blog/analyzing-sap-security-notes-october-2015
- http://www.securityfocus.com/bid/92062
- https://layersevensecurity.com/wp-content/uploads/2015/11/Layer-Seven-Security_SAP-Security-Notes_October-2015.pdf
- https://www.onapsis.com/blog/analyzing-sap-security-notes-october-2015
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.