CVE Database
/

CVE-2017-16687

Back to search

CVE-2017-16687

Published: Dec 12, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.

VendorProductVersions

SAP

SAP HANA extended application services

affected
SAP HANA Database 1.00, 2.00

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now