Medium severity5.3NVD Advisory· Published Dec 12, 2017· Updated May 13, 2026
CVE-2017-16687
CVE-2017-16687
Description
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
Affected products
3cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*
- cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:*
- SAP/SAP HANA extended application servicesv5Range: SAP HANA Database 1.00, 2.00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/102152nvdThird Party AdvisoryVDB Entry
- blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/nvdVendor Advisory
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.