Medium severity6.5NVD Advisory· Published Feb 14, 2018· Updated Jun 17, 2026
CVE-2018-2379
CVE-2018-2379
Description
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- SAP SE/SAP HANA Extended Application Servicesv5Range: 1.0
cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:*
- (no CPE)range: =1.0
Patches
Vulnerability mechanics
References
2- blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/nvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.