CVE-2018-2373
N/A
N/A
Summary
Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP SE | SAP HANA Extended Application Services | 1.0 | affected |
Weaknesses
- SQL Injection
ADP Enrichment
CVE Program Container
Additional References
- https://launchpad.support.sap.com/#/notes/2589129
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
References
- https://launchpad.support.sap.com/#/notes/2589129
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.