HANA Client Package Affected by Prototype Pollution Vulnerability
CVE-2024-45277
4.3MEDIUM
What is CVE-2024-45277?
The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
Affected Version(s)
SAP HANA Client HDB_CLIENT 2.0