VendorsSAPhana_extended_application_servicesany version
Vulnerabilities

SAP Hana Extended Application Services any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2015-1311
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2015-01-22 · Modified
10.0EPSS 0.022
CVE-2019-0363
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.
Published 2019-09-10 · Modified
7.1EPSS 0.009
CVE-2014-5173
SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public.
Published 2014-07-31 · Modified
5.0EPSS 0.028
CVE-2019-0364
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports.
Published 2019-09-10 · Modified
4.3EPSS 0.007
CVE-2014-5171
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.
Published 2014-07-31 · Modified
2.9EPSS 0.015