SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
BID:71022
Info
SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
| Bugtraq ID: | 71022 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8588 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2014 12:00AM |
| Updated: | Nov 04 2014 12:00AM |
| Credit: | Dmitry Chastukhin of ERPScan. |
| Vulnerable: |
SAP HANA 1.00.60.379371 |
| Not Vulnerable: | |
Discussion
SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
SAP HANA is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
SAP HANA 1.00.60.379371 is vulnerable; other versions may also be affected.
SAP HANA is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
SAP HANA 1.00.60.379371 is vulnerable; other versions may also be affected.
Exploit / POC
SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP HANA 'metadata.xsjs' SQL Injection Vulnerability
References:
References:
- SAP HANA HomePage (SAP )
- SQL injection vulnerability in SAP HANA (SAP)
- SAP Critical Patch Update October 2014 (ERPSCAN)
- SAP HANA Metadata.Xsjs �?? SQL Injection (erpscan)