CVE-2016-1928: Buffer Overflow
Published Jan 20, 2016
·Updated
Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security Note 2241978.
Affected Software
1 affected component
SAP HANA
Event History
Jan 20, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1928?
CVE-2016-1928 has been classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2016-1928?
To mitigate CVE-2016-1928, apply the latest patches and updates provided by SAP for the HANA software.
3
What are the potential impacts of CVE-2016-1928?
CVE-2016-1928 can lead to denial of service and unauthorized execution of arbitrary code, posing a significant risk to the affected systems.
4
Which versions of SAP HANA are affected by CVE-2016-1928?
CVE-2016-1928 affects all versions of SAP HANA that utilize the XS engine.
5
Can CVE-2016-1928 be exploited remotely?
Yes, CVE-2016-1928 can be exploited remotely using a crafted HTTP request.