### [CVE-2017-8915](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8915) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694. ### POC #### Reference - https://erpscan.io/advisories/erpscan-17-008-sap-hana-xs-sinopia-dos/ #### Github - https://github.com/vah13/SAP_vulnerabilities