CVE-2018-2377 is a medium-severity vulnerability affecting SAP HANA Extended Application Services 1.0, allowing unauthorized users to retrieve general server statistics and status information. With a CVSS score of 6.5, it presents a low-complexity network attack where an attacker with low privileges can achieve high confidentiality impact without requiring user interaction. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:sap:hana_extended_application_services:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.