Information Disclosure in SAP HANA Extended Application Services by SAP
CVE-2018-2376
8.1HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 February 2018
What is CVE-2018-2376?
In SAP HANA Extended Application Services version 1.0, a user with SpaceAuditor authorization within a specific space is able to access application environments, potentially exposing sensitive application data. This vulnerability highlights the importance of adequate access controls and permissions to prevent unauthorized data exposure.
Affected Version(s)
SAP HANA Extended Application Services 1.0