CVE-2018-2369 is an information disclosure vulnerability affecting SAP HANA versions 1.00 and 2.00. An unauthenticated attacker can exploit a flaw in the SQL interface's authentication function to disclose 8 bytes of server process memory. The CVSS score of 5.3 (Medium) indicates a low-complexity attack that requires no user interaction and results in limited confidentiality impact, as the attacker cannot control the leaked memory location. There is no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available. Community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning its resolution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00CPE matchmatch criteria | cpe:2.3:a:sap:hana:1.00:*:*:*:*:*:*:* | ||
2.00CPE matchmatch criteria | cpe:2.3:a:sap:hana:2.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.