CVE-2016-4018

HIGH

SAP HANA - Improper Access Control in Data Provisioning Agent

Title source: llm
STIX 2.1

Description

The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified other attacks via unspecified vectors, aka SAP Security Note 2262742.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 61.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-284
Status published
Products (1)
sap/hana
Published Apr 14, 2016
Tracked Since Feb 18, 2026