First published: Tue May 23 2017(Updated: )
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA XS | =1.00 | |
SAP HANA XS | =2.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8914 has a medium severity rating due to its potential for remote package hijacking.
To fix CVE-2017-8914, update your SAP HANA XS environment and implement secure user creation policies.
CVE-2017-8914 affects SAP HANA XS versions 1.00 and 2.00.
Yes, CVE-2017-8914 allows attackers to host arbitrary files due to an insecure user creation policy.
The risks associated with CVE-2017-8914 include unauthorized access to npm packages and potential system compromise.