NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21040 | CVE-2016-6147 | An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View | |
21039 | CVE-2016-6146 | The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226. | 2 | 5 | Medium | 2017-01-19 | 2016-09-28 | View | |
21038 | CVE-2016-6145 | The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
21037 | CVE-2016-6144 | The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
85336 | CVE-2016-6143 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | 2 | 7.5 | High | 2017-04-27 | 2017-04-20 | View |
Page 1462 of 17672, showing 5 records out of 88360 total, starting on record 7306, ending on 7310