First published: Tue May 23 2017(Updated: )
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA XS | =1.00 | |
SAP HANA XS | =2.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8915 is classified as a denial of service vulnerability that can crash the SAP HANA XS service.
To mitigate CVE-2017-8915, it is recommended to avoid pushing packages with filenames that include a $ (dollar sign) or % (percent) character.
CVE-2017-8915 affects users of SAP HANA XS versions 1.00 and 2.00.
Exploiting CVE-2017-8915 can lead to denial of service attacks causing service crashes.
Currently, there is no specific patch available for CVE-2017-8915; users should ensure proper filename handling to avoid the vulnerability.