SAPCVE-2026-44753
SAP HANA Extended Application: unauthenticated user could send specially...
Low3.7CVE-2026-44753 · Published Jul 14, 2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP HANA Extended Application Services classic model (User Self Service) Product | <= HDB 2.00 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-204
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP CRM (WebClient UI): attacker could inject | Medium4.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |