CVE Published: 12/12/2017 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: sap |
Vendor: SAP |
Product: SAP HANA extended application services Status : PUBLISHED
CVE-2017-16687 Description
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.