CVE Tools

Hana Extended Application Services

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Hana Extended Application Services, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Hana Extended Application Services CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Hana Extended Application Services CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High633%
  • Medium1056%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting Hana Extended Application Services.

  1. CVE-2019-0364Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports.4.3
  2. CVE-2019-0363Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ...7.1
  3. CVE-2019-0306SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete lis...4.3
  4. CVE-2019-0277SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External En...6.5
  5. CVE-2019-0266Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though t...7.5
  6. CVE-2018-2451XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, ...6.6
  7. CVE-2018-2373Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in S...7.5
  8. CVE-2018-2372A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.6.5
  9. CVE-2018-2379In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.6.5
  10. CVE-2018-2376In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.8.1
  11. CVE-2018-2377In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.6.5
  12. CVE-2018-2378In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.6.5
  13. CVE-2018-2375In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.8.1
  14. CVE-2018-2374In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that ...6.5
  15. CVE-2017-16680Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could ...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store