CVE-2016-3639: Infoleak
Published Sep 26, 2016
·Updated
SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified HTTP request, aka SAP Security Note 2176128.
Affected Software
1 affected component
SAP HANA DB=1.00.091.00.1418659308
Event History
Sep 26, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3639?
CVE-2016-3639 is classified as a low-severity vulnerability that allows exposure of sensitive topology information.
2
How do I fix CVE-2016-3639?
To mitigate CVE-2016-3639, apply the security patches provided in SAP Security Note 2176128.
3
What type of information can be disclosed through CVE-2016-3639?
CVE-2016-3639 can allow remote attackers to obtain sensitive topology information from the SAP HANA database.
4
Is CVE-2016-3639 exploitable remotely?
Yes, CVE-2016-3639 can be exploited remotely via an unspecified HTTP request.
5
Which version of SAP HANA DB is affected by CVE-2016-3639?
CVE-2016-3639 affects SAP HANA DB version 1.00.091.00.1418659308.