CVE-2018-2362: Medium severity sap hana database vulnerability
A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2362?
CVE-2018-2362 is a vulnerability in SAP HANA 1.00 and 2.00 that allows a remote unauthenticated attacker to disclose information such as the platform's hostname.
What is the severity of CVE-2018-2362?
The severity of CVE-2018-2362 is medium with a CVSS score of 5.3.
How can an attacker exploit CVE-2018-2362?
An attacker can exploit CVE-2018-2362 by sending specially crafted SOAP requests to the SAP Startup Service.
Which versions of SAP HANA are affected by CVE-2018-2362?
CVE-2018-2362 affects SAP HANA 1.00 and 2.00.
Are there any references or resources for CVE-2018-2362?
Yes, you can find more information about CVE-2018-2362 at the following links: [1] http://www.securityfocus.com/bid/102452 [2] https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/ [3] https://launchpad.support.sap.com/#/notes/2575750