CVE-2018-2379: Medium severity sap hana extended application services, advanced model vulnerability
Published Feb 14, 2018
·Updated
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
Affected Software
2 affected components
SAP HANA Extended Application Services=1.0
SAP HANA Extend Application Services=1.0
Event History
Feb 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2379?
CVE-2018-2379 has been assigned a medium severity rating due to its potential for information disclosure.
2
How does CVE-2018-2379 affect SAP HANA Extended Application Services?
CVE-2018-2379 allows an unauthenticated user to determine valid usernames by analyzing error messages.
3
How do I fix CVE-2018-2379?
To remediate CVE-2018-2379, it is recommended to apply the security patches provided by SAP for version 1.0 of the affected software.
4
Can CVE-2018-2379 be exploited remotely?
Yes, CVE-2018-2379 can be exploited remotely since it does not require authentication to test usernames.
5
What products are affected by CVE-2018-2379?
CVE-2018-2379 affects SAP HANA Extended Application Services and SAP HANA Extend Application Services, both version 1.0.