CVE-2017-16687
12.12.2017, 14:29
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.Enginsight
Vendor | Product | Version |
---|---|---|
sap | hana_database | 1.00 |
sap | hana_database | 2.00 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References