Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-2402


In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.


Published

2018-03-14T19:29:00.533

Last Modified

2024-11-21T04:03:45.263

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.6 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap hana 1.00 Yes
Application sap hana 2.00 Yes

References