Rewterz
Rewterz Threat Alert – Two Malspam Campaigns Detected
March 12, 2019
Rewterz
Rewterz Threat Advisory – CVE-2019-7094 – Adobe Photoshop Arbitrary Code Execution Vulnerability
March 13, 2019

Rewterz Threat Advisory – CVE-2019-0277 SAP HANA Extended Application Services

Severity

High

Analysis Summary

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

Impact

  • Exposure of sensitive information.
  • Denial of service.

Affected Products

SAP HANA Extended Application Services 1.0

Remediation

Updates are available.

Check vendor’s security note:

https://accounts.sap.com/saml2/idp/sso/accounts.sap.com