CVE-2016-6142: High severity sap hana database vulnerability
Published Sep 26, 2016
·Updated
SAP HANA DB 1.00.73.00.389160 (NewDB100REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
Affected Software
1 affected component
SAP HANA=1.00.73.00.389160
Event History
Sep 26, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6142?
CVE-2016-6142 has a medium severity rating due to the potential for arbitrary audit trail injection.
2
How do I fix CVE-2016-6142?
To fix CVE-2016-6142, apply the latest patches and updates provided by SAP for HANA DB.
3
Who is affected by CVE-2016-6142?
CVE-2016-6142 affects users of SAP HANA DB version 1.00.73.00.389160.
4
What type of attack does CVE-2016-6142 involve?
CVE-2016-6142 involves remote attackers injecting arbitrary fields into system logs via SQL protocol manipulation.
5
What can happen if CVE-2016-6142 is exploited?
If exploited, CVE-2016-6142 can allow unauthorized modifications to audit trails, compromising the integrity of the system.