VDB
CVE-2026-44753
CVE-2026-44753
PUBLISHED
CVSS 3.7 LOW
Reported by sap · Published July 14, 2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
Risk Scores
CVSS 3.1
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | HDB 2.00 |
| SAP_SE | SAP HANA Extended Application Services classic model (User Self Service) | HDB 2.00 |
Timeline
- Jul 14, 2026 EPSS Score
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 14, 2026 CVE Updated