SAP Security Note
High priority
SAP security note 2589129, “[CVE-2018-2374] Security vulnerabilities in SAP HANA Extended Application Services, advanced”, is a program error note released on 13.02.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
Under certain conditions, the SAP HANA XS Advanced server allows an attacker to access information which would otherwise be restricted. The vulnerability details along with their CVE relevant information can be found below.
A controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. (CVE-2018-2374)
Solution
The vulnerability has been fixed with SAP HANA Extended Application Services, advanced model version 1.0.70. Apply this or later versions.
CVSS
Score 7.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
References
- CVE-2018-2374
- CVE-2018-2375
- CVE-2018-2376
- CVE-2018-2379
- CVE-2018-2378
- CVE-2018-2377
- CVE-2018-2372
- CVE-2018-2373
Full note on SAP: SAP Support Launchpad note 2589129
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



