CVE-2017-16687 describes an information disclosure vulnerability in the user self-service tools of SAP HANA extended application services, classic user self-service, affecting SAP HANA Database versions 1.00 and 2.00. An unauthenticated attacker can exploit error messages to enumerate valid and invalid user accounts. With a CVSS score of 5.3 (Medium), this vulnerability has a low impact on confidentiality, requiring no user interaction or privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00CPE matchmatch criteria | cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:* | ||
2.00CPE matchmatch criteria | cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.