Information disclosure in SAP HANA - CVE-2018-2379
Published: February 19, 2018 / Updated: February 19, 2018
SAP HANA
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to evaluating error messages of a specific endpoint. A remote attacker can test if a given username is valid and gain access to potentially sensitive information.