PT-2018-15573 · Sap · Sap Hana Extended Application Services
Published
2018-08-14
·
Updated
2020-08-24
·
CVE-2018-2451
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP HANA Extended Application Services (XS) version 1
Description
The XS Command-Line Interface (CLI) user sessions may have an unintentional prolonged period of validity, allowing a platform user to access controller resources via an active CLI session even after authorizations have been revoked by an administrator. An attacker who gains access to the platform user's session could misuse the session token even after the session has been closed.
Recommendations
For SAP HANA Extended Application Services (XS) version 1, consider restricting access to the CLI until a fix is available to prevent unauthorized use of session tokens. As a temporary workaround, regularly close and re-authenticate CLI sessions to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Hana Extended Application Services