Home

Description

SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

PUBLISHED Reserved 2014-07-31 | Published 2014-07-31 | Updated 2024-10-21 | Assigner mitre

References

www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021

service.sap.com/sap/support/notes/1963932

www.securityfocus.com/bid/68947 (68947) vdb-entry

www.securityfocus.com/archive/1/532940/100/0/threaded (20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication) mailing-list

seclists.org/fulldisclosure/2014/Jul/149 (20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication) mailing-list

scn.sap.com/docs/DOC-8218

packetstormsecurity.com/...P-HANA-XS-Missing-Encryption.html

www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021

service.sap.com/sap/support/notes/1963932

www.securityfocus.com/bid/68947 (68947) vdb-entry

www.securityfocus.com/archive/1/532940/100/0/threaded (20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication) mailing-list

seclists.org/fulldisclosure/2014/Jul/149 (20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication) mailing-list

scn.sap.com/docs/DOC-8218

packetstormsecurity.com/...P-HANA-XS-Missing-Encryption.html

cve.org (CVE-2014-5171)

nvd.nist.gov (CVE-2014-5171)

Download JSON