Vulnerability Description
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Hana Extended Application Services | 1.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106988Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2724713Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
- http://www.securityfocus.com/bid/106988Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2724713Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943Vendor Advisory
FAQ
What is CVE-2019-0266?
CVE-2019-0266 is a vulnerability with a CVSS score of 7.5 (HIGH). Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this...
How severe is CVE-2019-0266?
CVE-2019-0266 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0266?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Hana Extended Application Services.