CVE-2024-45277

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:hana-client:*:*:*:*:*:node.js:*:*

History

14 Nov 2024, 17:54

Type Values Removed Values Added
References () https://me.sap.com/notes/3520100 - () https://me.sap.com/notes/3520100 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
References () https://www.npmjs.com/package/@sap/hana-client?activeTab=code - () https://www.npmjs.com/package/@sap/hana-client?activeTab=code - Product
CPE cpe:2.3:a:sap:hana-client:*:*:*:*:*:node.js:*:*
First Time Sap
Sap hana-client

10 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Las versiones del paquete de cliente SAP HANA Node.js de la 2.0.0 anterior a la 2.21.31 se ven afectadas por la vulnerabilidad de contaminación de prototipos, que permite a un atacante agregar propiedades arbitrarias a los prototipos de objetos globales. Esto se debe a una desinfección inadecuada de la entrada del usuario al utilizar la función nestTables, lo que tiene un impacto bajo en la disponibilidad de la aplicación. Esto no tiene impacto en la confidencialidad ni la integridad.

08 Oct 2024, 10:15

Type Values Removed Values Added
References
  • () https://www.npmjs.com/package/@sap/hana-client?activeTab=code -

08 Oct 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 04:15

Updated : 2024-11-14 17:54


NVD link : CVE-2024-45277

Mitre link : CVE-2024-45277

CVE.ORG link : CVE-2024-45277


JSON object : View

Products Affected

sap

  • hana-client
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')