CVE-2017-8914

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:hana_xs:1.00:*:*:*:*:*:*:*
cpe:2.3:a:sap:hana_xs:2.00:*:*:*:*:*:*:*

History

21 Nov 2024, 03:34

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/96206 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/96206 - Third Party Advisory, VDB Entry
References () https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/ - () https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/ -
References () https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/ - () https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/ -

Information

Published : 2017-05-23 04:29

Updated : 2024-11-21 03:34


NVD link : CVE-2017-8914

Mitre link : CVE-2017-8914

CVE.ORG link : CVE-2017-8914


JSON object : View

Products Affected

sap

  • hana_xs