Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0390 Information Disclosure in SAP Data Hub, SAP security note 2842034

Description

Under certain conditions SAP Data Hub allows an attacker to access information which would otherwise be restricted.
In detail, a connection and its details, that are maintained in Connection Manager are visible to users.

Available fix and Supported packages

  • DH_FOUNDATION | 2 | 2
  • SAP DATA HUB – FOUNDATION 2 | SP007 | 000000

Affected component

    EIM-DH
    SAP Data Hub: Please use CA-DI instead.

CVSS

Score: 5.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2842034

TAGS

#Information-Exposure
#Information-Leak
#&160-CVE-2019-0390

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.