Authentication Flaw in SAP HANA Extended Application Services
CVE-2019-0261

9.8CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
15 February 2019

Summary

The SAP HANA Extended Application Services (XS advanced) suffers from an authentication flaw which can allow unauthorized access under specific conditions. This vulnerability affects both the XS advanced platform and its business users, potentially exposing sensitive data and operations. Users are encouraged to upgrade to versions 1.0.97 through 1.0.99, which correct this issue when running on SAP HANA 1 or SAP HANA 2 SPS0.

Affected Version(s)

SAP HANA Extended Application Services < 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.