CVE-2019-0363: High severity sap hana extended application services, advanced model vulnerability
Published Sep 10, 2019
·Updated
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.
Affected Software
1 affected component
SAP HANA Extended Application Services<1.0.118
Event History
Sep 10, 2019
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0363?
CVE-2019-0363 has a medium severity level due to potential server overload and information disclosure risks.
2
How do I fix CVE-2019-0363?
To mitigate CVE-2019-0363, upgrade your SAP HANA Extended Application Services to version 1.0.118 or later.
3
What versions of SAP HANA Extended Application Services are affected by CVE-2019-0363?
CVE-2019-0363 affects SAP HANA Extended Application Services versions prior to 1.0.118.
4
What type of attack can be executed using CVE-2019-0363?
Using CVE-2019-0363, attackers can overload the server or retrieve sensitive internal network port information.
5
Is CVE-2019-0363 related to web applications?
Yes, CVE-2019-0363 is related to the HTTP/REST endpoints of the SAP HANA Extended Application Services web application.