CVE-2016-6145

UnknownEPSS 1.50%

Last modified

CVE-2016-6145 is a vulnerability of currently unknown severity. The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.

Description

The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.

Metrics

EPSS Probability
1.50%

71.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SapHana Db1.00.091.00.1418659308

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-6145?
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.
How severe is CVE-2016-6145?
Severity scoring for CVE-2016-6145 is pending analysis. The EPSS model estimates a 1.50% probability of exploitation in the next 30 days.
How do I fix CVE-2016-6145?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-6145?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST