CVE-2018-2376: High severity sap hana extended application services, advanced model vulnerability
Published Feb 14, 2018
·Updated
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.
Affected Software
2 affected components
SAP HANA Extended Application Services=1.0
SAP HANA Extend Application Services=1.0
Event History
Feb 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2376?
CVE-2018-2376 has a medium severity rating, indicating potential risk to affected systems.
2
How do I fix CVE-2018-2376?
To remediate CVE-2018-2376, update SAP HANA Extended Application Services to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2018-2376?
CVE-2018-2376 affects users with SpaceAuditor authorization in SAP HANA Extended Application Services, version 1.0.
4
What does CVE-2018-2376 allow an attacker to do?
CVE-2018-2376 allows a controller user with appropriate permissions to retrieve application environments within a specific space.
5
When was CVE-2018-2376 disclosed?
CVE-2018-2376 was disclosed as part of SAP's security patch day on February 13, 2018.