Description
SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_misc
https://erpscan.io/press-center/blog/sap-critical-patch-update-october-2014/
Various Sources x_refsource_misc
https://service.sap.com/sap/support/notes/2067972
Third Party Advisory x_refsource_misc
https://erpscan.io/advisories/erpscan-14-013-sap-hana-metadata-xsjs-sql-injection/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98579
Scores
EPSS
0.0040
EPSS Percentile
60.6%
Details
CWE
CWE-89
Status
published
Products (1)
sap/hana
1.00.60.379371
Published
Nov 04, 2014
Tracked Since
Feb 18, 2026