← back
CVE-2018-2402

CVE-2018-2402

CVSS 7.6 HIGHEPSS 1.6%
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.6EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
14 Mar 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
SAP SE · SAP HANA

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →