Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2374 Security vulnerabilities in SAP HANA Extended Application Services, advanced, SAP security note 2589129

SAP Note 2589129
SAP Security Note
High priority

SAP security note 2589129, “[CVE-2018-2374] Security vulnerabilities in SAP HANA Extended Application Services, advanced”, is a program error note released on 13.02.2018. Below are the symptom and SAP recommended solution.

ComponentBasis Components > HANA XS Advanced > XS Advanced Runtime / XS Controller
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version18
StatusReleased for Customer
Released on13.02.2018
LanguageEnglish

Description

Symptom

Under certain conditions, the SAP HANA XS Advanced server allows an attacker to access information which would otherwise be restricted. The vulnerability details along with their CVE relevant information can be found below.

A controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. (CVE-2018-2374)

Solution

The vulnerability has been fixed with SAP HANA Extended Application Services, advanced model version 1.0.70. Apply this or later versions.

CVSS

Score 7.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

References

  • CVE-2018-2374
  • CVE-2018-2375
  • CVE-2018-2376
  • CVE-2018-2379
  • CVE-2018-2378
  • CVE-2018-2377
  • CVE-2018-2372
  • CVE-2018-2373

Full note on SAP: SAP Support Launchpad note 2589129

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More