Executive brief
SAP HANA Database user self-service tools contain a flaw that allows unauthorized individuals to identify valid user accounts and email addresses. By sending specific requests and observing how the system responds, an attacker can map out existing users within the database. While this does not allow for direct data theft or system shutdown, it provides critical information that can be used to launch more targeted phishing or password-guessing attacks.
Technical details
An observable response discrepancy (CWE-204) exists in the SAP HANA Extended Application Services classic model (User Self Service). An unauthenticated remote attacker can send specially crafted requests to the self-service tools and distinguish between responses for valid and invalid users. This allows for the enumeration of valid user accounts and associated email addresses. The attack complexity is rated as high, likely due to the need for precise request crafting or timing analysis to differentiate responses. A fix is available via SAP Security Note 3732522.
Affected products
- SAP SE HANA Extended Application Services classic model (User Self Service) HDB 2.00
Timeline
- 2026-07-14: advisory: SAP Security Patch Day release
- 2026-07-14: disclosed: CVE published to NVD