{"api_version":"1","generated_at":"2026-07-23T11:46:41+00:00","cve":"CVE-2017-8914","urls":{"html":"https://cve.report/CVE-2017-8914","api":"https://cve.report/api/cve/CVE-2017-8914.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-8914","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-8914"},"summary":{"title":"CVE-2017-8914","description":"sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-05-23 04:29:02","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.3","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/","name":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SAP Cyber Threat Intelligence report – February 2017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/","name":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[ERPSCAN-17-009] SAP HANA Sinopia - default user creation policy insecure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96206","name":"http://www.securityfocus.com/bid/96206","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SAP HANA Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-8914","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8914","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"hana_xs","cpe6":"1.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8914","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"hana_xs","cpe6":"2.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:48:22.651Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"96206","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/96206"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-02-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-12-10T17:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"96206","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/96206"},{"tags":["x_refsource_MISC"],"url":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/"},{"tags":["x_refsource_MISC"],"url":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-8914","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"96206","refsource":"BID","url":"http://www.securityfocus.com/bid/96206"},{"name":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/","refsource":"MISC","url":"https://erpscan.io/advisories/erpscan-17-009-sap-hana-sinopia-default-user-creation-policy-insecure/"},{"name":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/","refsource":"MISC","url":"https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-february-2017/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-8914","datePublished":"2017-05-23T03:56:00.000Z","dateReserved":"2017-05-12T00:00:00.000Z","dateUpdated":"2024-08-05T16:48:22.651Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-23 04:29:02","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:hana_xs:1.00:*:*:*:*:*:*:*","matchCriteriaId":"ED07F990-5A46-4B07-BAF6-B4B8442F1FA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:hana_xs:2.00:*:*:*:*:*:*:*","matchCriteriaId":"CAAA84FF-06CF-4A08-8417-8DFC77CF6F38"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"8914","Ordinal":"1","Title":"CVE-2017-8914","CVE":"CVE-2017-8914","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"8914","Ordinal":"1","NoteData":"sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.","Type":"Description","Title":"CVE-2017-8914"},{"CveYear":"2017","CveId":"8914","Ordinal":"2","NoteData":"2017-05-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"8914","Ordinal":"3","NoteData":"2018-12-10","Type":"Other","Title":"Modified"}]}}}