Advisory
A note with CVSS 4.3 for component HAN-DB-CLI was released by SAP on 08.10.2024. The correction/advisory 3520100 was described with "[CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client" and affects the system type SAP HANA Client.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is weak security function within SAP HANA Client.
Risk specification
SAP HANA Client allows an authenticated attacker to add arbitrary properties to global object prototypes using the nestTables feature with a table named __proto__, resulting in a possible crash of the application.
Solution
Applications are no longer allowed to use the nestTables feature for a table named __proto__. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Do not use the feature nestTables or/and the table name __proto__.".
