{"cve":{"cve_id":"CVE-2019-0261","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.03629,"epss_percentile":0.88056,"epss_as_of":"2026-06-23","description":"Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).","published_at":"2019-02-15T18:00:00Z","last_modified_at":null,"cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943","https://launchpad.support.sap.com/#/notes/2742027","http://www.securityfocus.com/bid/106986"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:11:47.557720Z"},"effective_severity":null,"badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-hana-extended-application-services","product_name":"SAP HANA Extended Application Services","version_start":"< 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP                                                                                                               HANA 2 SPS0 (second S stands for stack)","version_start_inclusive":true,"version_end":"< 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP                                                                                                               HANA 2 SPS0 (second S stands for stack)","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-hana-extended-application-services:< 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP                                                                                                               HANA 2 SPS0 (second S stands for stack):< 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP                                                                                                               HANA 2 SPS0 (second S stands for stack)"}],"exploit_refs":[],"news":[],"references":[{"url":"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943","source_type":"MISC","tags":[]},{"url":"https://launchpad.support.sap.com/#/notes/2742027","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/bid/106986","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2019-02-15T18:00:00Z","label":"CVE published","source":null}]}