CVE-2016-6146: Infoleak
Published Sep 27, 2016
·Updated
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.
Affected Software
1 affected component
SAP TREX=7.10-revision_63
Event History
Sep 27, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6146?
CVE-2016-6146 has a medium severity level as it allows remote attackers to obtain sensitive TNS information.
2
How do I fix CVE-2016-6146?
To fix CVE-2016-6146, update to a patched version of SAP TREX that addresses this vulnerability.
3
What type of information can attackers obtain from CVE-2016-6146?
Attackers can obtain sensitive TNS information which may lead to further exploitation.
4
Which version of SAP TREX is affected by CVE-2016-6146?
SAP TREX version 7.10 Revision 63 is affected by CVE-2016-6146.
5
Is there any specific advisory for CVE-2016-6146?
Yes, SAP Security Note 2234226 provides details and guidance regarding CVE-2016-6146.