CyberRota Analysis
AI-GeneratedSAP HANA Database user self-service tools are vulnerable to unauthenticated requests that can be exploited to enumerate valid user accounts and email addresses. While the impact on confidentiality is low, this vulnerability could facilitate further attacks by revealing user information. Organizations using SAP HANA should prioritize remediation to mitigate potential risks associated with user enumeration.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.