← back
CVE-2018-2465

CVE-2018-2465

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.6%
exploitation probability
2.6%top 16% of all CVEs
observed exploitation
nono source reports it
In short

SAP HANA's OData parser fails to properly validate XML input, allowing attackers to crash the database server without authentication. This vulnerability affects the Extended Application Services component in versions 1.0 and 2.0.

Technical detail

The OData parser in SAP HANA EAS classic model lacks sufficient XML validation, enabling an unauthenticated attacker to submit malformed XML that triggers a denial-of-service condition resulting in database server crash. Attack vector is network-based through OData endpoints; no authentication required; impact is availability loss.

Summary generated and translated by AI from the official description.
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.
Affected products
SAP · SAP HANA