CVE-2019-0306: Medium severity sap hana extended application services, advanced model vulnerability
SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0306?
CVE-2019-0306 is classified as a medium severity vulnerability.
Who is affected by CVE-2019-0306?
CVE-2019-0306 affects authenticated low privileged XS Advanced Platform users, specifically SpaceAuditors, in SAP HANA Extended Application Services.
What is the impact of CVE-2019-0306?
The impact of CVE-2019-0306 is that low privileged users can obtain a complete list of SAP HANA user IDs and names without adequate permissions.
How do I fix CVE-2019-0306?
To fix CVE-2019-0306, you should update to the latest version of SAP HANA Extended Application Services.
What type of attack does CVE-2019-0306 relate to?
CVE-2019-0306 relates to unauthorized information disclosure that allows low privileged users to access sensitive user data.