PT-2024-7176 · Sap · Sap Hana Node.Js Client Package

CVE-2024-45277

·

Published

2024-10-07

·

Updated

2024-11-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SAP HANA Node.js client package versions 2.0.0 through 2.21.30
Description The issue is related to a Prototype Pollution vulnerability in the SAP HANA Node.js client package, specifically affecting the nestTables feature. This vulnerability allows an attacker to add arbitrary properties to global object prototypes due to improper user input sanitation. The exploitation of this issue may cause low impact on the availability of the application, with no impact on Confidentiality and Integrity.
Recommendations For SAP HANA Node.js client package versions 2.0.0 through 2.21.30, update to version 2.21.31 or later to resolve the issue. As a temporary workaround, consider disabling the nestTables feature until a patch is available. Restrict access to the vulnerable nestTables function to minimize the risk of exploitation. Avoid using the nestTables feature in the affected API endpoints until the issue is resolved.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08515
CVE-2024-45277
GHSA-6339-GV7W-G5F4

Affected Products

Sap Hana Node.Js Client Package