SAP HANA 1.00.095.00.1429086950 Log Injection

Discussion in 'News Aggregator' started by Packet Storm, 18 Apr 2016.

  1. Packet Storm

    Packet Storm Guest

    Anonymous attackers can use a special HTTP request to inject logs in the xsengine trace file without size restriction. The vulnerability is triggered when the username sent to the /sap/hana/xs/debugger/grantAccess.xscfunc page is longer than 256 characters.

    Continue reading...
     

Share This Page

Loading...