CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92961  CVE-2016-6141  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160701)  None (candidate not yet proposed)    View
92962  CVE-2016-6142  Candidate  SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.  Assigned (20160701)  None (candidate not yet proposed)    View
92963  CVE-2016-6143  Candidate  SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.  Assigned (20160701)  None (candidate not yet proposed)    View
92964  CVE-2016-6144  Candidate  The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869.  Assigned (20160701)  None (candidate not yet proposed)    View
92965  CVE-2016-6145  Candidate  The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.  Assigned (20160701)  None (candidate not yet proposed)    View

Page 18593 of 20943, showing 5 records out of 104715 total, starting on record 92961, ending on 92965

Actions