what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 18 of 18 RSS Feed

Files from Sergio Abraham

First Active2014-06-06
Last Active2016-10-11
SAPCRYPTOLIB 5.555.38 Missing Signature Check
Posted Oct 11, 2016
Authored by Fernando Russ, Sergio Abraham, Pablo Artuso | Site onapsis.com

SAPCRYPTOLIB version 5.555.38 suffers from a missing signature check in its DSA algorithm.

tags | advisory
advisories | CVE-2016-4407
SHA-256 | c57e938e01fd374e72b21d0aa73cc8d0c2ca106f33d2addda4e763f24c2e5a95
SAP Netweaver 7.4 UCON Security Protection Bypass
Posted Oct 11, 2016
Authored by Sergio Abraham, Pablo Muller | Site onapsis.com

SAP Netweaver version 7.4 suffers from a UCON security protection bypass vulnerability.

tags | advisory, bypass
advisories | CVE-2016-3635
SHA-256 | b6b6da161f5f6d99d64676628f359e1d03196f8e0db85b8e37097dc37b2fefce
SAP Netweaver 2004s Invalid Address Logging
Posted Oct 3, 2016
Authored by Sergio Abraham | Site onapsis.com

SAP Netweaver 2004s suffers from a Security Audit Log invalid address logging issue.

tags | advisory
advisories | CVE-2016-4551
SHA-256 | 209e6e26f282e79e950659858428ce65950b8a6438be686c8d03d5c3ba43079f
SAP HANA DB Encryption Issue
Posted Aug 20, 2016
Authored by Sergio Abraham | Site onapsis.com

An error in the implementation results in no authentication/encryption being done for tenants services in "high isolation" mode on SAP HANA DB.

tags | advisory
advisories | CVE-2016-6150
SHA-256 | c6551122b9fa4cbc6499321204eb298ebec9e485d4e308ec1c7723979c014023
SAP TREX 7.10 Revision 63 Remote Command Execution
Posted Aug 20, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham, Nahuel Sanchez | Site onapsis.com

SAP TREX version 7.10 revision 63 suffers from a remote command execution vulnerability.

tags | advisory, remote
advisories | CVE-2016-6147
SHA-256 | 0819be6c462080645727510772e93d336c75a8827da0a93033522577a8a61c8c
SAP TREX 7.10 Revision 63 NameServer TNS Information Disclosure
Posted Aug 20, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham, Nahuel Sanchez | Site onapsis.com

SAP TREX version 7.10 revision 63 suffers from a TNS information disclosure vulnerability in NameServer.

tags | advisory, info disclosure
advisories | CVE-2016-6146
SHA-256 | 7b9adee861d5e668126c4a179eb39eaad2ab92fa481b23b056ff2cb62d5297a1
SAP TREX 7.10 Revision 63 Arbitrary File Write
Posted Aug 19, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

SAP TREX 7.10 revision 63 suffers from an arbitrary file write vulnerability.

tags | advisory, arbitrary
advisories | CVE-2016-6140
SHA-256 | 5a99e7f7eae9d9a3066219049450db19d95da02530af7b6a5e101a1da4c7ddff
SAP TREX 7.10 Revision 63 Remote File Read
Posted Aug 19, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

SAP TREX 7.10 revision 63 suffers from a remote file read vulnerability.

tags | advisory, remote
advisories | CVE-2016-6139
SHA-256 | e3509536f1ca1b383605ab1ab9d476c85a741c1fa9c35209743c2a2e449c5690
SAP TREX 7.10 Revision 63 Directory Traversal
Posted Aug 19, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

SAP TREX 7.10 revision 63 suffers from a remote directory traversal vulnerability.

tags | advisory, remote
advisories | CVE-2016-6138
SHA-256 | ba4abc7db7d764d9cf3ca72412bc129f86fb9296f37112f744602a22fb11e0cf
SAP TREX 7.10 Revision 63 Remote Command Execution
Posted Aug 19, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

SAP TREX 7.10 revision 63 suffers from a remote command execution vulnerability.

tags | advisory, remote
advisories | CVE-2016-6137
SHA-256 | 57335d49d9f144bf86626dce42926f6e8d20c20f3641c7437a2982b8a8a46953
SAP HANA DB 1.00.091.00.1418659308 Password Disclosure
Posted Aug 19, 2016
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

SAP HANA DB version 1.00.091.00.1418659308 suffers from a password disclosure vulnerability.

tags | advisory
advisories | CVE-2016-3640
SHA-256 | 20d119aebb419f9c23fcacb993de3aea0f03fe535415bd530f18ffac68545a77
SAP HANA Remote Trace Disclosure
Posted Nov 9, 2015
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham | Site onapsis.com

Due to a flaw in SAP HANA DB version 1.00.73.00.389160, a remote unauthenticated attacker could read remote logs containing technical information about the system which could help to facilitate further attacks against the system.

tags | advisory, remote
advisories | CVE-2015-7991
SHA-256 | fd289a49117a0a823798ba0eed96cdc41815b67bc8c0a02046f5482b8e5ad75b
SAP HANA TrexNet Command Execution
Posted Nov 9, 2015
Authored by Juan Pablo Perez Etchegoyen, Sergio Abraham, Nahuel Sanchez | Site onapsis.com

Using the multiple methods available in the TrexNet protocol, a remote unauthenticated attacker could execute arbitrary operating system commands, python modules, read, write and delete files and directories, read environment information and also completely shut down the SAP HANA instance. The attacker could also send TMS queries to the NameSever component, which could allow him to retrieve technical information of the remote system such as configuration files. SAP HANA Database versions 1.00 SPS10 and below are affected.

tags | advisory, remote, arbitrary, protocol, python
advisories | CVE-2015-7828
SHA-256 | e4cccb6ea9d715363678d97b705a3ed4cfae92d173b1157c598542160cec7a0e
SAP HANA Information Disclosure
Posted May 27, 2015
Authored by Fernando Russ, Nahuel D. Sanchez, Sergio Abraham | Site onapsis.com

Onapsis Security Advisory - SAP HANA suffers from an information disclosure vulnerability via SQL IMPORT FROM statements.

tags | advisory, info disclosure
advisories | CVE-2015-3995
SHA-256 | bb14e2959b52d187e9b6acc4384e410e0927c0d33b3653e304b8da39ef6615f8
SAP FI Manager Self-Service Hardcoded Username
Posted Jul 29, 2014
Authored by Sergio Abraham | Site onapsis.com

Onapsis Security Advisory - SAP FI Manager Self-Service contains a hardcoded username which could allow a user to access functions or information that should be restricted.

tags | advisory
SHA-256 | 6af964bfb323ace71af49db49e9c09318bd3bd26ffd097eee87a3bcf28af33bb
SAP HANA IU5 SDK Authentication Bypass
Posted Jul 29, 2014
Authored by Sergio Abraham | Site onapsis.com

Onapsis Security Advisory - SAP HANA IU5 SDK Application does not enforce any authentication when it is explicitly configured. It could allow an anonymous user to access functions or information that should be restricted.

tags | advisory
SHA-256 | 012319929550f40aff45210c9e107a59b2e67cadbe0eba2ea67d08b03dc14274
SAP HANA XS Missing Encryption
Posted Jul 29, 2014
Authored by Manuel Muradas, Sergio Abraham | Site onapsis.com

Onapsis Security Advisory - SAP HANA XS does not enforce any encryption in the form based authentication. It could allow an anonymous user to get information such as valid credentials from network traffic, gaining access into the system.

tags | advisory
SHA-256 | 3c59882224f4e683e1189c962e0c8f1e472ad02e008d6bd4c6be59028fba9d6b
SAP Hard-Coded Credentials
Posted Jun 6, 2014
Authored by Sergio Abraham | Site onapsis.com

Onapsis Security Advisory - Various SAP systems suffer from hard-coded credential vulnerabilities.

tags | advisory, vulnerability
SHA-256 | f19ce8f84128aec4f22198225fcc61a16d9b7f54df40ed479627b26a8c0f4efb
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close