CVE-2018-2369

3 documents3 sources
Severity
5.3MEDIUM
EPSS
0.7%
top 27.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateMay 13

Description

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDsap/hana1.00, 2.00+1
CVEListV5sap_se/sap_hana1.00, 2.00+1

🔴Vulnerability Details

2
GHSA
GHSA-xfj8-jfv4-fhr6: Under certain conditions SAP HANA, 12022-05-13
CVEList
CVE-2018-2369: Under certain conditions SAP HANA, 12018-02-14