CVE-2015-7993: Input Validation
Published Nov 10, 2015
·Updated
The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100REL) allows remote attackers to execute arbitrary code via unspecified vectors related to "HTTP Login," aka SAP Security Note 2197397.
Affected Software
1 affected component
SAP HANA=1.00.73.00.389160
Event History
Nov 10, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7993?
CVE-2015-7993 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2015-7993?
To fix CVE-2015-7993, it is recommended to apply the latest patches provided by SAP for the affected version.
3
What types of attacks are possible with CVE-2015-7993?
CVE-2015-7993 allows remote attackers to execute arbitrary code, which can lead to complete system compromise.
4
Is CVE-2015-7993 exploitable without authentication?
Yes, CVE-2015-7993 can be exploited remotely, potentially without authentication, depending on the application configuration.
5
Which version of SAP HANA is affected by CVE-2015-7993?
CVE-2015-7993 affects SAP HANA DB version 1.00.73.00.389160.