First published: Fri May 29 2015(Updated: )
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA Database | =1.00.73.00.389160 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3995 is considered a high severity vulnerability due to its potential for information disclosure.
To fix CVE-2015-3995, apply the recommended security patches provided in SAP Security Note 2109565.
CVE-2015-3995 affects remote authenticated users of SAP HANA database version 1.00.73.00.389160.
CVE-2015-3995 allows authenticated users to read arbitrary files from the server via an IMPORT FROM SQL statement.
As of the latest reports, there is no public indication of active exploitation of CVE-2015-3995.