7.5
CVE-2018-2373
- EPSS 0.77%
- Veröffentlicht 14.02.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:42
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Hana Extended Application Services Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.726 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|