CVE-2024-45277

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:hana-client:*:*:*:*:*:node.js:*:*

History

14 Nov 2024, 17:54

Type Values Removed Values Added
First Time Sap
Sap hana-client
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:sap:hana-client:*:*:*:*:*:node.js:*:*
References () https://www.npmjs.com/package/@sap/hana-client?activeTab=code - () https://www.npmjs.com/package/@sap/hana-client?activeTab=code - Product
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
References () https://me.sap.com/notes/3520100 - () https://me.sap.com/notes/3520100 - Permissions Required

08 Oct 2024, 10:15

Type Values Removed Values Added
References
  • () https://www.npmjs.com/package/@sap/hana-client?activeTab=code -

08 Oct 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-08 04:15

Updated : 2024-11-14 17:54


NVD link : CVE-2024-45277

Mitre link : CVE-2024-45277


JSON object : View

Products Affected

sap

  • hana-client
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')