SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-2497

The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

LOW 2.7EPSS 0.93%

Does this matter?

Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.

Description

The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

CVSS 3.0
2.7 LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Affected
sap/hana
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.