CVE-2018-2369: Medium severity sap hana database vulnerability
Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP HANA vulnerability?
The vulnerability ID for this SAP HANA vulnerability is CVE-2018-2369.
What is the severity level of CVE-2018-2369?
The severity level of CVE-2018-2369 is medium, with a severity value of 5.3.
How can an unauthenticated attacker access restricted information in SAP HANA 1.00 and 2.00?
An unauthenticated attacker can misuse the authentication function of the SAP HANA server on its SQL interface to access 8 bytes of the server process memory.
Which versions of SAP HANA are affected by CVE-2018-2369?
CVE-2018-2369 affects SAP HANA 1.00 and 2.00.
Where can I find more information about CVE-2018-2369?
You can find more information about CVE-2018-2369 on securityfocus.com, blogs.sap.com, and launchpad.support.sap.com.