Impact
A flaw in the SAP HANA database allows an authenticated user to switch to the session of another user, which can result in administrative access. The effect is a full compromise of confidentiality, integrity, and availability. The root weakness is an authorization flaw (CWE‑306).
Affected Systems
SAP SE’s SAP HANA database is affected. No specific release or version information is provided in the CNA data.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, but the EPSS score is under 1 %, showing a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is authenticated application‑level access, requiring a valid user credential to trigger the privilege escalation.
OpenCVE Enrichment