The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
References
Configurations
History
21 Nov 2024, 02:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/57443 - Vendor Advisory | |
References | () http://www.onapsis.com/get.php?resid=adv_onapsis-2014-001 - | |
References | () http://www.onapsis.com/research-advisories.php - | |
References | () http://www.securityfocus.com/bid/66675 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/92325 - | |
References | () https://service.sap.com/sap/support/notes/1914778 - |
Information
Published : 2014-04-10 20:55
Updated : 2024-11-21 02:06
NVD link : CVE-2014-2749
Mitre link : CVE-2014-2749
CVE.ORG link : CVE-2014-2749
JSON object : View
Products Affected
sap
- hana
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor