Vulnerability Name: | CVE-2014-5171 (CCN-94930) | ||||||||
Assigned: | 2014-07-29 | ||||||||
Published: | 2014-07-29 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network. | ||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N) 2.1 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.1 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-5171 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html Source: CONFIRM Type: UNKNOWN http://scn.sap.com/docs/DOC-8218 Source: CCN Type: Full Disclosure Mailing List, Tue, 29 Jul 2014 11:53:47 -0300 SAP HANA XS Missing encryption in form-based authentication Source: FULLDISC Type: UNKNOWN 20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication Source: MISC Type: UNKNOWN http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021 Source: BUGTRAQ Type: UNKNOWN 20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication Source: BID Type: UNKNOWN 68947 Source: CCN Type: BID-68947 SAP HANA Extended Application Services CVE-2014-5171 Information Disclosure Vulnerability Source: XF Type: UNKNOWN sap-hanaxs-info-disc(94930) Source: CCN Type: SAP Web site SAP Support Note 1963932 Source: CONFIRM Type: UNKNOWN https://service.sap.com/sap/support/notes/1963932 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |