PT-2015-6379 · Sap · Sap Hana Db

Fernando Russ

+2

·

Published

2015-05-29

·

Updated

2018-10-09

·

CVE-2015-3995

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP HANA DB version 1.00.73.00.389160
Description The issue allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement.
Recommendations For SAP HANA DB version 1.00.73.00.389160, consider restricting access to the IMPORT FROM SQL statement until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3995

Affected Products

Sap Hana Db