SAP TREX 7.10 NameServer Vulnerability
CVE-2016-6146

5.3MEDIUM

Key Information:

Vendor

SAP

Status
Vendor
CVE Published:
27 September 2016

What is CVE-2016-6146?

The NameServer component in SAP TREX 7.10 Revision 63 contains a vulnerability that allows remote attackers to gain access to sensitive TNS information through an unspecified query. This issue raises significant security concerns as it could lead to unauthorized access to sensitive data, potentially compromising system integrity and confidentiality. It is critical for organizations using this version to implement the necessary security updates and monitor their systems for unusual activity.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.