VDB

CVE-2026-44753

CVE-2026-44753 PUBLISHED CVSS 3.7 LOW

Reported by sap · Published July 14, 2026

SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.

Risk Scores

CVSS 3.1
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SAP_SESAP HANA Extended Application Services classic model (User Self Service)HDB 2.00
SAP_SESAP HANA Extended Application Services classic model (User Self Service)HDB 2.00

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›