First published: Wed Feb 14 2018(Updated: )
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA Extended Application Services, Advanced Model | =1.0 | |
SAP HANA Extended Application Services | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2379 has been assigned a medium severity rating due to its potential for information disclosure.
CVE-2018-2379 allows an unauthenticated user to determine valid usernames by analyzing error messages.
To remediate CVE-2018-2379, it is recommended to apply the security patches provided by SAP for version 1.0 of the affected software.
Yes, CVE-2018-2379 can be exploited remotely since it does not require authentication to test usernames.
CVE-2018-2379 affects SAP HANA Extended Application Services and SAP HANA Extend Application Services, both version 1.0.