cbcvebase.
CVE-2019-0284
published 2019-04-10

CVE-2019-0284: SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can…

PriorityP430medium6CVSS 3.0
AVLACLPRHUINSUCHINAH
EPSS
0.35%
27.4th percentile
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary files and even send local files.

Affected

4 ranges
VendorProductVersion rangeFixed in
saphana
saphana
sap_sesap_hana< 1.01.0
sap_sesap_hana< 2.02.0

CVSS provenance

nvdv3.06.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.