SAP

Hana Extended Application Services

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Published 10.09.2019 17:15:11
  • Last modified 21.11.2024 04:16:44

Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports.

  • EPSS 0.37%
  • Published 10.09.2019 17:15:11
  • Last modified 21.11.2024 04:16:44

Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.

  • EPSS 0.2%
  • Published 12.06.2019 15:29:00
  • Last modified 21.11.2024 04:16:39

SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names.

  • EPSS 0.78%
  • Published 12.03.2019 22:29:00
  • Last modified 21.11.2024 04:16:37

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

  • EPSS 0.39%
  • Published 15.02.2019 18:29:02
  • Last modified 21.11.2024 04:16:36

Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access,...

  • EPSS 0.47%
  • Published 14.08.2018 16:29:01
  • Last modified 21.11.2024 04:03:50

XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via...

  • EPSS 0.29%
  • Published 14.02.2018 12:29:00
  • Last modified 21.11.2024 04:03:42

In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

  • EPSS 0.75%
  • Published 14.02.2018 12:29:00
  • Last modified 21.11.2024 04:03:42

In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.

  • EPSS 0.29%
  • Published 14.02.2018 12:29:00
  • Last modified 21.11.2024 04:03:42

In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.

  • EPSS 0.29%
  • Published 14.02.2018 12:29:00
  • Last modified 21.11.2024 04:03:42

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.