PT-2018-15507 · Sap · Sap Hana Extended Application Services

CVE-2018-2374

·

Publicado

2018-02-14

·

Atualizado

2023-12-21

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP HANA Extended Application Services version 1.0
Description A controller user with SpaceAuditor authorization in a specific space could retrieve sensitive application data, such as service bindings, within that space.
Recommendations For SAP HANA Extended Application Services version 1.0, restrict access to the SpaceAuditor authorization to minimize the risk of sensitive data retrieval.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-2374

Produtos afetados

Sap Hana Extended Application Services