Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-2402

Опубликовано: 14 мар. 2018
Источник: nvd
CVSS3: 7.6
CVSS3: 8.4
CVSS2: 3.5
EPSS Низкий

Описание

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:hana:1.00:*:*:*:*:*:*:*
cpe:2.3:a:sap:hana:2.00:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00271
Низкий

7.6 High

CVSS3

8.4 High

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.4
github
больше 3 лет назад

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

EPSS

Процентиль: 50%
0.00271
Низкий

7.6 High

CVSS3

8.4 High

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200