CVE-2015-7729
https://notcve.org/view.php?id=CVE-2015-7729
Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892. Inyección eval en test-net.xsjs en el Web-based Development Workbench en SAP HANA Developer Edition DB 1.00.091.00.1418659308 permite a usuarios remotos autenticados ejecutar código XSJS arbitrario a través de vectores no especificados, también conocida como SAP Security Note 2153892. • http://packetstormsecurity.com/files/133763/SAP-HANA-test-net.xsjs-Code-Injection.html http://seclists.org/fulldisclosure/2015/Sep/112 https://www.onapsis.com/blog/analyzing-sap-security-notes-may-2015-edition https://www.onapsis.com/research/security-advisories/sap-hana-xsjs-code-injection-test-net • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2015-7728
https://notcve.org/view.php?id=CVE-2015-7728
Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898. Vulnerabilidad de XSS en la creación de usuario en el Web-based Development Workbench en SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través del nombre de usuario, también conocida como SAP Security Note 2153898. • http://seclists.org/fulldisclosure/2015/Sep/116 https://www.onapsis.com/blog/analyzing-sap-security-notes-may-2015-edition https://www.onapsis.com/research/security-advisories/sap-hana-xss-user-creation-through-web-based-development • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-7727
https://notcve.org/view.php?id=CVE-2015-7727
Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors in the (1) trace configuration page or (2) getSqlTraceConfiguration function, aka SAP Security Note 2153898. Múltiples vulnerabilidades de inyección SQL en el Web-based Development Workbench en SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados en la (1) página trace configuration o (2) función getSqlTraceConfiguration, también conocidas como SAP Security Note 2153898. • http://packetstormsecurity.com/files/133766/SAP-HANA-Trace-Configuration-SQL-Injection.html http://packetstormsecurity.com/files/133768/SAP-HANA-getSqlTraceConfiguration-SQL-Injection.html http://seclists.org/fulldisclosure/2015/Sep/115 http://seclists.org/fulldisclosure/2015/Sep/117 http://www.onapsis.com/research/security-advisories/SAP-HANA-Trace-configuration-SQL-injection https://www.onapsis.com/blog/analyzing-sap-security-notes-may-2015-edition https://www.onapsis.com/research/security-advisories/sap-hana-sql- • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2015-7726
https://notcve.org/view.php?id=CVE-2015-7726
Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allows remote authenticated users to inject arbitrary web script or HTML via the role name, aka SAP Security Note 2153898. Vulnerabilidad de XSS en la eliminación de rol en el Web-based Development Workbench en SAP HANA DB 1.00.091.00.1418659308 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través del nombre de rol, también conocida como SAP Security Note 2153898. • http://seclists.org/fulldisclosure/2015/Sep/114 https://www.onapsis.com/blog/analyzing-sap-security-notes-may-2015-edition https://www.onapsis.com/research/security-advisories/sap-hana-xss-role-deletion-through-web-based-workbench • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-7725
https://notcve.org/view.php?id=CVE-2015-7725
Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allow remote authenticated users to execute arbitrary SQL commands via the (1) remoteSourceName in the dropCredentials function or unspecified vectors in the (2) setTraceLevelsForXsApps, (3) _modifyUser, or (4) _newUser function, aka SAP Security Notes 2153898 and 2153765. Múltiples vulnerabilidades de inyección SQL en el Web-based Development Workbench en SAP HANA DB 1.00.091.00.1418659308 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de (1) remoteSourceName en la función dropCredentials o vectores no especificados en la función (2) setTraceLevelsForXsApps, (3) _modifyUser o (4) _newUser, también conocidas como SAP Security Notes 2153898 y 2153765. • http://packetstormsecurity.com/files/133761/SAP-HANA-_modifyUser-SQL-Injection.html http://packetstormsecurity.com/files/133762/SAP-HANA-_newUser-SQL-Injection.html http://packetstormsecurity.com/files/133764/SAP-HANA-setTraceLevelsForXsApps-SQL-Injection.html http://packetstormsecurity.com/files/133769/SAP-HANA-Drop-Credentials-SQL-Injection.html http://seclists.org/fulldisclosure/2015/Sep/110 http://seclists.org/fulldisclosure/2015/Sep/111 http://seclists.org/fulldisclosure/2015/Sep/113 http://seclists.org • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •