ZeroHour

CVE-2017-8914

CVSS 3.0
8.3 high
EPSS
1%p73
Published
()
Modified
Description

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.

Vendors
sap
Products
hana xs
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.