VulnerabilityModified
CVE-2018-2465
By exploiting, an unauthorized hacker can cause the database server to crash.
HIGH 7.5EPSS 2.56%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sap/hana
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/105324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2681207Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993Vendor Advisory
- http://www.securityfocus.com/bid/105324Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2681207Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.