← Back

CVE-2017-8914

nvd nist
Published: May 23, 2017Modified: May 13, 2026

JSON object

Loading...
8.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.7
Source: NVD

Description

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.

Affected (2)

Products: Sap: Hana Xs
1 product
Hana Xs
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 1.00
Version 2.00

Timeline

No history available yet.