CVE-2017-16687: Infoleak
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16687?
CVE-2017-16687 is a vulnerability in the user self-service tools of SAP HANA extended application services, classic user self-service, that allows an unauthenticated user to determine if a given username is valid.
What is the severity of CVE-2017-16687?
CVE-2017-16687 has a severity value of 5.3, which is considered medium.
How can the user self-service tools of SAP HANA Database be misused?
The user self-service tools of SAP HANA Database can be misused to enumerate valid and invalid user accounts.
Which versions of SAP HANA Database are affected by CVE-2017-16687?
CVE-2017-16687 affects SAP HANA Database versions 1.00 and 2.00.
How can I fix CVE-2017-16687?
To fix CVE-2017-16687, it is recommended to apply the security patch provided by SAP.