CVE-2019-0261
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.63% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- sap/landscape management
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/106986Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2742027Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
- http://www.securityfocus.com/bid/106986Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2742027Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.