CVE-2018-2378: Medium severity sap hana extended application services, advanced model vulnerability
Published Feb 14, 2018
·Updated
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.
Affected Software
2 affected components
SAP HANA Extended Application Services=1.0
SAP HANA Extend Application Services=1.0
Event History
Feb 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2378?
CVE-2018-2378 is considered a medium severity vulnerability.
2
How do I fix CVE-2018-2378?
To fix CVE-2018-2378, apply the latest security patches provided by SAP for HANA Extended Application Services 1.0.
3
What data can unauthorized users access in CVE-2018-2378?
Unauthorized users can access statistical data about deployed applications, including resource consumption metrics.
4
Which versions of SAP HANA are affected by CVE-2018-2378?
CVE-2018-2378 affects SAP HANA Extended Application Services version 1.0.
5
Is there a way to mitigate CVE-2018-2378 without patching?
Mitigation for CVE-2018-2378 involves restricting access to sensitive configuration settings until patches are applied.