Vulnerability record · CVE-2018-2402 · published 14 March 2018
CVE-2018-2402: Sap hana information exposure vulnerability
Sap · Hana
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.
Description
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103369 | Third Party AdvisoryVDB Entry |
| https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/ | Vendor Advisory |
| https://launchpad.support.sap.com/#/notes/2587369 | Permissions RequiredVendor Advisory |
| http://www.securityfocus.com/bid/103369 | Third Party AdvisoryVDB Entry |
| https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/ | Vendor Advisory |
| https://launchpad.support.sap.com/#/notes/2587369 | Permissions RequiredVendor Advisory |
Track CVE-2018-2402 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-2402), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.