SAP
SAP Hana Extended Application Services: vulnerabilidades y CVE
SAP Hana Extended Application Services tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-0364 | Media (4.3) | 0.70% | — | 10 sept 2019 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports. |
| CVE-2019-0363 | Alta (7.1) | 0.90% | — | 10 sept 2019 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports. |
| CVE-2019-0306 | Media (4.3) | 0.88% | — | 12 jun 2019 | SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs… |
| CVE-2019-0277 | Media (6.5) | 2.1% | — | 12 mar 2019 | SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). |
| CVE-2019-0266 | Alta (7.5) | 1.8% | — | 15 feb 2019 | Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is… |
| CVE-2018-2451 | Media (6.6) | 1.2% | — | 14 ago 2018 | XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could… |
| CVE-2018-2379 | Media (6.5) | 0.89% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. |
| CVE-2018-2378 | Media (6.5) | 0.85% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption. |
| CVE-2018-2377 | Media (6.5) | 0.85% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. |
| CVE-2018-2376 | Alta (8.1) | 0.92% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. |
| CVE-2018-2375 | Alta (8.1) | 0.92% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. |
| CVE-2018-2374 | Media (6.5) | 1.2% | — | 14 feb 2018 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. |
| CVE-2018-2373 | Alta (7.5) | 1.1% | — | 14 feb 2018 | Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended… |
| CVE-2018-2372 | Media (6.5) | 0.85% | — | 14 feb 2018 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. |
| CVE-2017-16680 | Alta (7.5) | 1.7% | — | 12 dic 2017 | Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could allow unprivileged… |
| CVE-2015-1311 | Alta (10) | 2.2% | — | 22 ene 2015 | The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details… |
| CVE-2014-5173 | Media (5) | 2.8% | — | 31 jul 2014 | SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public. |
| CVE-2014-5171 | Baja (2.9) | 1.5% | — | 31 jul 2014 | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive… |
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29