CVE-2016-6144: High severity sap hana database vulnerability
The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the passwordlockforsystemuser is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6144?
CVE-2016-6144 has a medium severity rating due to its potential for exploitation through brute force attacks.
How do I fix CVE-2016-6144?
To fix CVE-2016-6144, ensure that the password_lock_for_system_user setting is enabled to limit login attempts for the SYSTEM user.
Who is affected by CVE-2016-6144?
CVE-2016-6144 affects all versions of SAP HANA prior to Revision 102 that do not have the password_lock_for_system_user configuration supported or set to true.
What kind of attack does CVE-2016-6144 expose systems to?
CVE-2016-6144 exposes systems to brute force attacks targeting the SYSTEM user login.
What are the implications of not addressing CVE-2016-6144?
Failing to address CVE-2016-6144 can lead to unauthorized access and potential data breaches by allowing attackers to systematically guess user credentials.