Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2589129 | permissions required |
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ | vendor advisory |