#VU10635 Information disclosure in SAP HANA - CVE-2018-2369
Published: February 19, 2018 / Updated: February 19, 2018
SAP HANA
SAP
Description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to misusing of the authentication function of the SAP HANA server on its SQL interface. A remote attacker can disclose 8 bytes of the server process memory and gain access to potentially sensitive information.