CVE-2014-5171
 
Severity Score
2.9
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.
SAP HANA Extend Application Services (XS) no codifica las transmisiones para aplicaciones que habilitan la autenticaciĆ³n basada en formularios utilizando SSL, lo que permite a atacantes remotos obtener credenciales y otra informaciĆ³n sensible mediante la captura del trafico de la red.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-07-31 CVE Reserved
- 2014-07-31 CVE Published
- 2023-03-07 EPSS Updated
- 2024-10-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html | X_refsource_misc | |
http://scn.sap.com/docs/DOC-8218 | X_refsource_confirm | |
http://seclists.org/fulldisclosure/2014/Jul/149 | Mailing List | |
http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021 | X_refsource_misc | |
http://www.securityfocus.com/archive/1/532940/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/68947 | Vdb Entry | |
https://service.sap.com/sap/support/notes/1963932 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Hana Extended Application Services Search vendor "Sap" for product "Hana Extended Application Services" | - | - |
Affected
|