CVE-2016-6859: SAP Hybris

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace.

Affected products

  • SAP Hybris: any version

Published 2016-12-31. Last modified 2026-06-17.