CVE-2026-44753: Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44753?
CVE-2026-44753 has a low severity rating of 3.7.
How can CVE-2026-44753 be exploited?
CVE-2026-44753 can be exploited by an unauthenticated user sending specially crafted requests to enumerate valid user accounts and email addresses.
What software is affected by CVE-2026-44753?
CVE-2026-44753 affects the SAP HANA Extended Application Services classic model and SAP HANA Database.
What is the potential impact of CVE-2026-44753?
The potential impact of CVE-2026-44753 includes the risk of an attacker enumerating valid user accounts.
How do I mitigate CVE-2026-44753?
Mitigating CVE-2026-44753 involves applying any available patches and securing user self-service tools to restrict unauthorized access.