CVE-2015-1311: Code Injection
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1311?
CVE-2015-1311 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2015-1311?
To fix CVE-2015-1311, apply the latest SAP patches as advised in security updates.
What types of software are affected by CVE-2015-1311?
CVE-2015-1311 affects SAP HANA Extend Application Services and SAP HANA Extended Application Services.
Can CVE-2015-1311 lead to data breaches?
Yes, CVE-2015-1311 can lead to unauthorized access and data breaches through remote code execution.
Is CVE-2015-1311 specific to certain versions of SAP software?
CVE-2015-1311 affects unspecified versions of SAP HANA Extended Application Services and should be checked against SAP's advisory for specific details.