In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2589129 | permissions required |
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ | vendor advisory |