CVE-2014-5171
Status: ModifiedLow (2.9)—
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.
CVSS
- Version: 2.0
- Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N
- Base score: 2.9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.52%
- Percentile among all scored CVEs: 74
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-310
References
- http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html
- http://scn.sap.com/docs/DOC-8218
- http://seclists.org/fulldisclosure/2014/Jul/149
- http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021
- http://www.securityfocus.com/archive/1/532940/100/0/threaded
- http://www.securityfocus.com/bid/68947
- https://service.sap.com/sap/support/notes/1963932
- http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html
- http://scn.sap.com/docs/DOC-8218
- http://seclists.org/fulldisclosure/2014/Jul/149
- http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021
- http://www.securityfocus.com/archive/1/532940/100/0/threaded
- http://www.securityfocus.com/bid/68947
- https://service.sap.com/sap/support/notes/1963932
Raw JSON (NVD)
Show
{
"id": "CVE-2014-5171",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2014-5171",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-14T16:46:03.862982Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.9,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-07-31T14:55:04.097",
"references": [
{
"url": "http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html",
"source": "cve@mitre.org"
},
{
"url": "http://scn.sap.com/docs/DOC-8218",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Jul/149",
"source": "cve@mitre.org"
},
{
"url": "http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/532940/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/68947",
"source": "cve@mitre.org"
},
{
"url": "https://service.sap.com/sap/support/notes/1963932",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://scn.sap.com/docs/DOC-8218",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Jul/149",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/532940/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/68947",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://service.sap.com/sap/support/notes/1963932",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network."
},
{
"lang": "es",
"value": "SAP HANA Extend Application Services (XS) no codifica las transmisiones para aplicaciones que habilitan la autenticación basada en formularios utilizando SSL, lo que permite a atacantes remotos obtener credenciales y otra información sensible mediante la captura del trafico de la red."
}
],
"lastModified": "2026-06-17T00:11:09.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:hana_extended_application_services:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FF40963-C288-484C-9EB0-84E3FC84127E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}