SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2016/Aug/108 | mailing list |
http://packetstormsecurity.com/files/138456/SAP-HANA-SPS09-1.00.091.00.1418659308-EXPORT-Information-Disclosure.html | |
https://www.onapsis.com/research/security-advisories/sap-hana-information-disclosure-export | third party advisory permissions required |
https://www.onapsis.com/blog/analyzing-sap-security-notes-january-2016 | third party advisory |
http://www.securityfocus.com/bid/92061 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2016/Aug/97 | mailing list |