Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-2451


XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been revoked meanwhile by an administrator user. Similarly, an attacker who managed to gain access to the platform user's session might misuse the session token even after the session has been closed.


Published

2018-08-14T16:29:01.693

Last Modified

2024-11-21T04:03:50.337

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.6 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap hana_extended_application_services 1.0 Yes

References