Total vulnerabilities in the database
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
Software | From | Fixed in |
---|---|---|
sap / hana_database | 2.00 | 2.00.x |
sap / hana_database | 1.00 | 1.00.x |