CVE-2018-2369
CVE-2018-2369
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Feb 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.
Affected products
SAP SE · SAP HANAWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →