VulnerabilityModified
CVE-2014-2749
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
MEDIUM 5.0EPSS 1.51%
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/hana
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/57443Vendor Advisory
- http://www.onapsis.com/get.php?resid=adv_onapsis-2014-001
- http://www.onapsis.com/research-advisories.php
- http://www.securityfocus.com/bid/66675
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92325
- https://service.sap.com/sap/support/notes/1914778
- http://secunia.com/advisories/57443Vendor Advisory
- http://www.onapsis.com/get.php?resid=adv_onapsis-2014-001
- http://www.onapsis.com/research-advisories.php
- http://www.securityfocus.com/bid/66675
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92325
- https://service.sap.com/sap/support/notes/1914778
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.