CVE-2018-2369

MEDIUM

SAP HANA 1.00, 2.00 - Unauthenticated Information Disclosure via SQL Interface

Title source: llm
STIX 2.1

Description

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102997
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/2572940

Scores

CVSS v3 5.3
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (2)
sap/hana 1.00
sap/hana 2.00
Published Feb 14, 2018
Tracked Since Feb 18, 2026