CVE-2017-8915: High severity sap hana extended application services vulnerability
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8915?
CVE-2017-8915 is classified as a denial of service vulnerability that can crash the SAP HANA XS service.
How do I fix CVE-2017-8915?
To mitigate CVE-2017-8915, it is recommended to avoid pushing packages with filenames that include a $ (dollar sign) or % (percent) character.
Who is affected by CVE-2017-8915?
CVE-2017-8915 affects users of SAP HANA XS versions 1.00 and 2.00.
What types of attacks can CVE-2017-8915 lead to?
Exploiting CVE-2017-8915 can lead to denial of service attacks causing service crashes.
Is there a patch available for CVE-2017-8915?
Currently, there is no specific patch available for CVE-2017-8915; users should ensure proper filename handling to avoid the vulnerability.