Information disclosure in SAP HANA - CVE-2018-2369
Published: February 19, 2018 / Updated: February 19, 2018
SAP HANA
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to misusing of the authentication function of the SAP HANA server on its SQL interface. A remote attacker can disclose 8 bytes of the server process memory and gain access to potentially sensitive information.