CVE-2016-6144 describes a critical authentication bypass vulnerability in SAP HANA, specifically affecting versions prior to Revision 102. This flaw allows remote attackers to conduct brute-force attacks against the SYSTEM user due to an unlimited number of login attempts when the password_lock_for_system_user setting is disabled or unsupported. With a CVSS score of 8.1 (HIGH), successful exploitation could lead to complete compromise of confidentiality, integrity, and availability of the affected SAP HANA system. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.00.73.00.389160CPE matchmatch criteria | cpe:2.3:a:sap:hana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.