CVE-2015-7727: SQL Injection
Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100REL) allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors in the (1) trace configuration page or (2) getSqlTraceConfiguration function, aka SAP Security Note 2153898.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7727?
CVE-2015-7727 is classified with a medium severity due to its potential to allow authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2015-7727?
To fix CVE-2015-7727, it is recommended to apply the latest security patches provided by SAP for HANA version 1.00.73.00.389160.
What versions of SAP HANA are affected by CVE-2015-7727?
CVE-2015-7727 affects SAP HANA version 1.00.73.00.389160.
What types of vulnerabilities are present in CVE-2015-7727?
CVE-2015-7727 includes multiple SQL injection vulnerabilities that can be exploited via the trace configuration page and the getSqlTraceConfiguration function.
Who can exploit the vulnerabilities in CVE-2015-7727?
The vulnerabilities in CVE-2015-7727 can be exploited by remote authenticated users with access to the affected SAP HANA system.