Vulnerabilities > CVE-2017-8914 - Unspecified vulnerability in SAP Hana XS 1.00/2.00

047910
CVSS 8.3 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
network
low complexity
sap

Summary

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.

Vulnerable Configurations

Part Description Count
Application
Sap
2