CVE-2016-6859: Infoleak
Published Dec 31, 2016
·Updated
Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace.
Affected Software
1 affected component
SAP Hybris
Event History
Dec 31, 2016
CVE Published
via MITRE·06:56 AM
Data Sourced
via MITRE·06:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6859?
CVE-2016-6859 is considered a medium severity vulnerability due to its potential for information disclosure.
2
How can I fix CVE-2016-6859?
To fix CVE-2016-6859, it is recommended to upgrade to SAP Hybris version 6.0 or later.
3
What type of vulnerability is CVE-2016-6859?
CVE-2016-6859 is an information disclosure vulnerability.
4
Who is affected by CVE-2016-6859?
CVE-2016-6859 affects all versions of SAP Hybris prior to 6.0.
5
What kind of exposure does CVE-2016-6859 allow?
CVE-2016-6859 allows remote attackers to obtain sensitive information by exploiting error handling mechanisms.