CVE-2014-5171

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
31/07/2014
Last modified:
12/04/2025

Description

SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:hana_extended_application_services:-:*:*:*:*:*:*:*