CVE-2015-7991: Infoleak
Published Nov 10, 2015
·Updated
The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100REL) allows remote attackers to read web dispatcher and security trace files and possibly obtain passwords via unspecified vectors, aka SAP Security Note 2148854.
Affected Software
1 affected component
SAP HANA=1.00.73.00.389160
Event History
Nov 10, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7991?
CVE-2015-7991 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-7991?
To fix CVE-2015-7991, apply the latest patches and updates provided by SAP for HANA DB.
3
What kind of data can be exposed due to CVE-2015-7991?
CVE-2015-7991 can potentially expose web dispatcher and security trace files, including passwords.
4
Which versions of SAP HANA are affected by CVE-2015-7991?
CVE-2015-7991 affects SAP HANA DB version 1.00.73.00.389160.
5
Can CVE-2015-7991 be exploited remotely?
Yes, CVE-2015-7991 allows remote attackers to exploit the vulnerability without requiring physical access.