Information disclosure in SAP HANA - CVE-2018-2373
Published: February 19, 2018 / Updated: February 19, 2018
SAP HANA
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists due to misuse of a specific endpoint of the Controller's API. A remote attacker can execute SQL statements that deliver information about system configuration and gain access to potentially sensitive information.