Описание
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Permissions RequiredVendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*
cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00877
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
EPSS
Процентиль: 75%
0.00877
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200