SQL Interface Vulnerability in SAP HANA DB by SAP
CVE-2016-6145
5.3MEDIUM
What is CVE-2016-6145?
The SQL interface of SAP HANA DB has a design flaw that allows a remote attacker to differentiate between valid and invalid usernames based on specific error messages. When the detailed_error_on_connect option is not supported or set to 'False', the system provides varying responses during failed login attempts. This discrepancy creates an opportunity for attackers to enumerate valid usernames through a series of login trials, potentially leading to unauthorized access or further exploitation of the database. The vulnerability highlights the importance of secure configurations and error handling in database management systems.