CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
92961 | CVE-2016-6141 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160701) | None (candidate not yet proposed) | View | |
92962 | CVE-2016-6142 | Candidate | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459. | Assigned (20160701) | None (candidate not yet proposed) | View | |
92963 | CVE-2016-6143 | Candidate | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | Assigned (20160701) | None (candidate not yet proposed) | View | |
92964 | CVE-2016-6144 | Candidate | The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869. | Assigned (20160701) | None (candidate not yet proposed) | View | |
92965 | CVE-2016-6145 | Candidate | The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869. | Assigned (20160701) | None (candidate not yet proposed) | View |
Page 18593 of 20943, showing 5 records out of 104715 total, starting on record 92961, ending on 92965