CVE-2019-0266: SAP Hana Extended Application Services

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased.

Affected products

  • SAP Hana Extended Application Services: version 1.0 only

Published 2019-02-15. Last modified 2026-06-17.