SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Hana Extended Application Services Classic Model (user Self Service)
Vendors & Products Sap Se
Sap Se sap Hana Extended Application Services Classic Model (user Self Service)

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
Title Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2026-07-14T00:19:58.321Z

Updated: 2026-07-14T12:38:29.089Z

Reserved: 2026-05-07T18:31:04.066Z

Link: CVE-2026-44753

cve-icon Vulnrichment

Updated: 2026-07-14T12:38:25.561Z

cve-icon NVD

No data.

cve-icon Redhat

No data.