PT-2018-15509 · Sap · Sap Hana Extended Application Services

CVE-2018-2376

·

Publicado

2018-02-14

·

Atualizado

2023-12-21

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP HANA Extended Application Services version 1.0
Description A controller user with SpaceAuditor authorization in a specific space could retrieve application environments within that space.
Recommendations For SAP HANA Extended Application Services version 1.0, restrict access to the SpaceAuditor authorization to minimize the risk of unauthorized application environment retrieval.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-2376

Produtos afetados

Sap Hana Extended Application Services