Advisory
On 14.07.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP HANA Platform.
SAP Note 3732522 addresses "3732522 - [CVE-2026-44753] - Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)" to prevent information disclosure with a low risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Information disclosure is when an application fails to properly protect sensitive and confidential information from
parties that are not supposed to have access to the subject matter in normal circumstances.
Carefully review every information disclosure vulnerablity in regards to disclosure obligations post-GDPR for
‘Personal data’ under the Data Protection Act 2018.
Risk specification
SAP HANA Database (User Self-Service Tools) allows an unauthenticated attacker to send specially crafted requests that produce distinguishable responses, potentially resulting in the enumeration of valid user accounts and email addresses.
Solution
Error handling in the SAP HANA XS Classic User Self-Service has been improved to return a generic error message for all requests, preventing user enumeration through response differentiation. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "Disabling the XSC user self service functionality.".
