Unrated severityNVD Advisory· Published Jul 31, 2014· Updated Jun 17, 2026
CVE-2014-5171
CVE-2014-5171
Description
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:sap:hana_extended_application_services:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:hana_extended_application_services:-:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.htmlnvd
- scn.sap.com/docs/DOC-8218nvd
- seclists.org/fulldisclosure/2014/Jul/149nvd
- www.onapsis.com/resources/get.phpnvd
- www.securityfocus.com/archive/1/532940/100/0/threadednvd
- www.securityfocus.com/bid/68947nvd
- service.sap.com/sap/support/notes/1963932nvd
News mentions
0No linked articles in our index yet.