VulnerabilityModified
CVE-2018-2497
The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.
LOW 2.7EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.
- CVSS 3.0
- 2.7 LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- sap/hana
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/106152Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2704878Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=508559699Vendor Advisory
- http://www.securityfocus.com/bid/106152Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2704878Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=508559699Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.