VYPR
Medium severity6.0NVD Advisory· Published Apr 10, 2019· Updated Jun 17, 2026

CVE-2019-0284

CVE-2019-0284

Description

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary files and even send local files.

Affected products

4
  • SAP/Hana3 versions
    cpe:2.3:a:sap:hana:1.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:hana:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:hana:2.0:*:*:*:*:*:*:*
    • (no CPE)range: 1.0, 2.0
  • SAP SE/SAP HANAv5
    Range: < 1.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.