First published: Tue Oct 27 2015(Updated: )
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA Database | <=1.00.095 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7986 is classified as a critical vulnerability due to its potential for remote code execution and denial of service.
To remediate CVE-2015-7986, it is recommended to update SAP HANA to a version that is not vulnerable, specifically beyond version 1.00.095.
CVE-2015-7986 affects all users of SAP HANA version 1.00.095 and earlier.
CVE-2015-7986 can be exploited by remote attackers through crafted HTTP requests leading to arbitrary code execution or memory corruption.
CVE-2015-7986 is considered widespread due to the common deployment of SAP HANA in enterprise environments.