PT-2018-15509 · Sap · Sap Hana Extended Application Services
CVE-2018-2376
·
Publicado
2018-02-14
·
Atualizado
2023-12-21
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP HANA Extended Application Services version 1.0
Description
A controller user with SpaceAuditor authorization in a specific space could retrieve application environments within that space.
Recommendations
For SAP HANA Extended Application Services version 1.0, restrict access to the SpaceAuditor authorization to minimize the risk of unauthorized application environment retrieval.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Hana Extended Application Services