CVE-2016-6145: Infoleak
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailederroronconnect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6145?
CVE-2016-6145 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2016-6145?
To mitigate CVE-2016-6145, ensure that the detailed_error_on_connect option is enabled to prevent different error messages for failed login attempts.
What type of attack is possible with CVE-2016-6145?
CVE-2016-6145 allows remote attackers to enumerate valid usernames and potentially exploit account lockout mechanisms.
Which software versions are affected by CVE-2016-6145?
CVE-2016-6145 specifically affects SAP HANA DB version 1.00.091.00.1418659308.
Can CVE-2016-6145 be exploited remotely?
Yes, CVE-2016-6145 can be exploited remotely by attackers attempting to gather user account information.