Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-6144

The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.0%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 4.3
Products affected by CVE-2016-6144
  • Sap » Hana » Version: N/A
    cpe:2.3:a:sap:hana:-
  • Sap » Hana » Version: 1.0
    cpe:2.3:a:sap:hana:1.0
  • Sap » Hana » Version: 1.00
    cpe:2.3:a:sap:hana:1.00


Contact Us

Shodan ® - All rights reserved