VYPR
High severity8.3NVD Advisory· Published May 23, 2017· Updated May 13, 2026

CVE-2017-8914

CVE-2017-8914

Description

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.

Affected products

2
  • SAP/Hana Xs2 versions
    cpe:2.3:a:sap:hana_xs:1.00:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:hana_xs:1.00:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:hana_xs:2.00:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.