CVE-2019-0357: High severity sap hana database vulnerability
Published Sep 10, 2019
·Updated
The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.
Affected Software
2 affected components
SAP HANA=1.0
SAP HANA=2.0
Event History
Sep 10, 2019
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SAP HANA database vulnerability?
The vulnerability ID is CVE-2019-0357.
2
What is the severity level of CVE-2019-0357?
The severity level of CVE-2019-0357 is high.
3
Which versions of SAP HANA are affected by CVE-2019-0357?
Versions 1.0 and 2.0 of SAP HANA are affected by CVE-2019-0357.
4
What can an administrator of SAP HANA database do to misuse HANA and execute commands?
An administrator of SAP HANA database can misuse HANA to execute commands with operating system "root" privileges.
5
Where can I find more information about CVE-2019-0357?
More information about CVE-2019-0357 can be found at the following references: [1] https://launchpad.support.sap.com/#/notes/2829681 [2] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506