SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka SAP Security Note 2233136.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/138450/SAP-HANA-DB-1.00.73.00.389160-Remote-Code-Execution.html | |
https://www.onapsis.com/blog/analyzing-sap-security-notes-january-2016 | third party advisory |
https://layersevensecurity.com/wp-content/uploads/2016/02/Layer-Seven-Security_SAP-Security-Notes_January-2016.pdf | technical description |
http://seclists.org/fulldisclosure/2016/Aug/95 | mailing list |
http://www.securityfocus.com/bid/92067 | vdb entry third party advisory |