SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.
References
Configurations
Information
Published : 2014-07-31 07:55
Updated : 2018-10-09 12:49
NVD link : CVE-2014-5171
Mitre link : CVE-2014-5171
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
sap
- hana_extend_application_services