The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 02:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://secunia.com/advisories/57443 - Vendor Advisory | |
| References | () http://www.onapsis.com/get.php?resid=adv_onapsis-2014-001 - | |
| References | () http://www.onapsis.com/research-advisories.php - | |
| References | () http://www.securityfocus.com/bid/66675 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/92325 - | |
| References | () https://service.sap.com/sap/support/notes/1914778 - | 
Information
                Published : 2014-04-10 20:55
Updated : 2025-04-12 10:46
NVD link : CVE-2014-2749
Mitre link : CVE-2014-2749
CVE.ORG link : CVE-2014-2749
JSON object : View
Products Affected
                sap
- hana
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
