CVE-2018-2497: SAP Hana

Low severity, CVSS 2.7. EPSS: 0.9% chance of exploitation in the next 30 days.

The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

Affected products

  • SAP Hana: version 1.0 only; version 2.0 only

Published 2018-12-11. Last modified 2026-06-17.