Back to search
CVE-2015-7727
Published: Oct 15, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors in the (1) trace configuration page or (2) getSqlTraceConfiguration function, aka SAP Security Note 2153898.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150929 [Onapsis Security Advisory 2015-022] SAP HANA SQL injection in getSqlTraceConfiguration function
mailing-list
x_refsource_FULLDISC
20150929 [Onapsis Security Advisory 2015-020] SAP HANA Trace configuration SQL injection
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now