CVE-2018-2465: SAP Hana

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.

Affected products

  • SAP Hana: version 1.0 only; version 2.0 only

Published 2018-09-11. Last modified 2026-06-17.