The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap hana-client |
|
CPEs | cpe:2.3:a:sap:hana-client:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Sap
Sap hana-client |
Tue, 08 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap Se
Sap Se sap Hana Client |
|
CPEs | cpe:2.3:a:sap_se:sap_hana_client:*:*:*:*:*:*:*:* | |
Vendors & Products |
Sap Se
Sap Se sap Hana Client |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 08 Oct 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity. | |
Title | Prototype Pollution vulnerability in SAP HANA Client | |
Weaknesses | CWE-1321 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-10-08T03:21:16.236Z
Updated: 2024-10-08T14:01:44.271Z
Reserved: 2024-08-26T10:39:20.931Z
Link: CVE-2024-45277
Vulnrichment
Updated: 2024-10-08T14:01:31.948Z
NVD
Status : Analyzed
Published: 2024-10-08T04:15:08.133
Modified: 2024-11-14T17:54:28.373
Link: CVE-2024-45277
Redhat
No data.