CVE-2019-0364: Medium severity sap hana extended application services, advanced model vulnerability
Published Sep 10, 2019
·Updated
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports.
Affected Software
1 affected component
SAP HANA Extended Application Services<1.0.118
Event History
Sep 10, 2019
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0364?
CVE-2019-0364 is classified as a medium-severity vulnerability due to the potential for information disclosure.
2
How do I fix CVE-2019-0364?
To remediate CVE-2019-0364, upgrade SAP HANA Extended Application Services to version 1.0.118 or later.
3
What systems are affected by CVE-2019-0364?
CVE-2019-0364 affects SAP HANA Extended Application Services versions prior to 1.0.118.
4
What can attackers do with CVE-2019-0364?
Attackers can misuse the vulnerability to enumerate open ports via the HTTP/REST endpoint.
5
Is CVE-2019-0364 actively exploited in the wild?
As of now, there have been no confirmed reports of active exploitation of CVE-2019-0364.