CVE-2018-2372 describes a vulnerability in SAP HANA Extended Application Services, 1.0, where a plain keystore password is inadvertently written to a system log file, compromising the confidentiality of SSL communication. This medium-severity vulnerability has a CVSS score of 6.5, indicating it can be exploited remotely with low complexity by an authenticated user, leading to a high impact on confidentiality. Despite its potential to expose sensitive information, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered limited community discussion and media coverage, with one article from SecurityWeek noting SAP's resolution in February 2018.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.