Sap hana Extended Application Services Access Restriction Bypass Vulnerability
Release date:
Updated on: 2014-08-02
Affected Systems:
Sap hana Extended Application Services
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68950
CVE (CAN) ID: CVE-2014-5173
Sap hana Extended Application Services (XS) is the development environment for Web applications in the Application server, Web server, and sap hana System.
Sap hana Extend Application Services (XS) has a security vulnerability that allows remote attackers to bypass access restrictions by requesting private IU5 SDK applications.
<* Source: Sergio Abraham
Link: http://seclists.org/fulldisclosure/2014/Jul/153
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://service.sap.com/sap/support/notes/1993349
This article permanently updates the link address: