CVE-2019-0306: SAP Hana Extended Application Services

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names.

Affected products

  • SAP Hana Extended Application Services: version 1.0 only

Published 2019-06-12. Last modified 2026-06-17.