Session Management Vulnerability in SAP HANA Extended Application Services
CVE-2018-2451
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 August 2018
What is CVE-2018-2451?
The SAP HANA Extended Application Services (XS) has a session management flaw in its Command-Line Interface (CLI), which can lead to prolonged session validity. This issue allows previously authorized platform users to maintain access to controller resources even after their permissions have been revoked by administrators. Furthermore, it poses a risk of session hijacking, as an attacker can exploit the session token of a user who has already closed their session, gaining unauthorized access to sensitive resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP HANA Extended Application Services 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved