CVE-2014-5171
Summary
| CVE | CVE-2014-5171 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-31 14:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:A/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Hana Extended Application Services | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Onapsis - Register | af854a3a-2127-422b-91ae-364da2661108 | www.onapsis.com | |
| SAP HANA XS Missing Encryption ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| service.sap.com/sap/support/notes/1963932 | af854a3a-2127-422b-91ae-364da2661108 | service.sap.com | |
| Full Disclosure: [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Acknowledgments to Security Researchers | SCN | af854a3a-2127-422b-91ae-364da2661108 | scn.sap.com | |
| SAP HANA Extended Application Services CVE-2014-5171 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.