CVE-2019-0261: SAP Landscape Management

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).

Affected products

  • SAP Landscape Management: version 3.0 only

Published 2019-02-15. Last modified 2026-06-17.