{"api_version":"1","generated_at":"2026-07-23T12:02:18+00:00","cve":"CVE-2014-5171","urls":{"html":"https://cve.report/CVE-2014-5171","api":"https://cve.report/api/cve/CVE-2014-5171.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5171","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5171"},"summary":{"title":"CVE-2014-5171","description":"SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-07-31 14:55:04","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.9","severity":"","vector":"AV:A/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:N/A:N","baseScore":2.9,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/532940/100/0/threaded","name":"http://www.securityfocus.com/archive/1/532940/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021","name":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Onapsis - Register","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html","name":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SAP HANA XS Missing Encryption ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://service.sap.com/sap/support/notes/1963932","name":"https://service.sap.com/sap/support/notes/1963932","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://seclists.org/fulldisclosure/2014/Jul/149","name":"http://seclists.org/fulldisclosure/2014/Jul/149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Full Disclosure: [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://scn.sap.com/docs/DOC-8218","name":"http://scn.sap.com/docs/DOC-8218","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Acknowledgments to Security Researchers | SCN","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68947","name":"http://www.securityfocus.com/bid/68947","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SAP HANA Extended Application Services CVE-2014-5171 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5171","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5171","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5171","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"hana_extended_application_services","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:34:37.549Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://service.sap.com/sap/support/notes/1963932"},{"name":"68947","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/68947"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/532940/100/0/threaded"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Jul/149"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://scn.sap.com/docs/DOC-8218"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2014-5171","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-02-14T16:46:03.862982Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-10-21T16:50:44.135Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-07-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021"},{"tags":["x_refsource_CONFIRM"],"url":"https://service.sap.com/sap/support/notes/1963932"},{"name":"68947","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/68947"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/532940/100/0/threaded"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2014/Jul/149"},{"tags":["x_refsource_CONFIRM"],"url":"http://scn.sap.com/docs/DOC-8218"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-5171","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021","refsource":"MISC","url":"http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-021"},{"name":"https://service.sap.com/sap/support/notes/1963932","refsource":"CONFIRM","url":"https://service.sap.com/sap/support/notes/1963932"},{"name":"68947","refsource":"BID","url":"http://www.securityfocus.com/bid/68947"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/532940/100/0/threaded"},{"name":"20140729 [Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2014/Jul/149"},{"name":"http://scn.sap.com/docs/DOC-8218","refsource":"CONFIRM","url":"http://scn.sap.com/docs/DOC-8218"},{"name":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/127666/SAP-HANA-XS-Missing-Encryption.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-5171","datePublished":"2014-07-31T14:00:00.000Z","dateReserved":"2014-07-31T00:00:00.000Z","dateUpdated":"2024-10-21T16:50:44.135Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-07-31 14:55:04","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:N/A:N","baseScore":2.9,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":5.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:hana_extended_application_services:-:*:*:*:*:*:*:*","matchCriteriaId":"9FF40963-C288-484C-9EB0-84E3FC84127E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5171","Ordinal":"1","Title":"CVE-2014-5171","CVE":"CVE-2014-5171","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5171","Ordinal":"1","NoteData":"SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.","Type":"Description","Title":"CVE-2014-5171"},{"CveYear":"2014","CveId":"5171","Ordinal":"2","NoteData":"2014-07-31","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5171","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}