Skip to main content

Vendor/product archive

sap / hana CVEs

Beta · best-effort

38 CVEs tagged to sap / hana6 Critical, 13 High, 16 Medium, 3 Low, 0 Unrated.

CVE-2021-21484

Published Mar 9, 2021

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-0357

Published Sep 10, 2019

The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0284

Published Apr 10, 2019

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XM…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-2497

Published Dec 11, 2018

The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2465

Published Sep 11, 2018

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the da…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2018-2402

Published Mar 14, 2018

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may b…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-2369

Published Feb 14, 2018

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authenticat…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-2362

Published Jan 9, 2018

A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's ho…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6143

Published Apr 13, 2017

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6142

Published Sep 26, 2016

SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Securi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6150

Published Aug 5, 2016

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6148

Published Aug 5, 2016

SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6144

Published Aug 5, 2016

The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is con…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4018

Published Apr 14, 2016

The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, g…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4017

Published Apr 14, 2016

The Data Provisioning Agent (aka DP Agent) in SAP HANA allows remote attackers to cause a denial of service (process crash) via unspecified vectors, aka SAP Security Note 2262710.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1929

Published Jan 20, 2016

The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1928

Published Jan 20, 2016

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7994

Published Nov 10, 2015

The SQL interface in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related to "SQL Login," aka SAP Securit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7993

Published Nov 10, 2015

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7992

Published Nov 10, 2015

SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to cause a denial of service (memory corruption and indexserver crash) via unspecified vectors to th…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7991

Published Nov 10, 2015

The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files and possibly obtain passwords vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7828

Published Nov 10, 2015

SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified other impact via a TrexNet pack…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7986

Published Oct 27, 2015

The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7729

Published Oct 15, 2015

Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7728

Published Oct 15, 2015

Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 38 CVEsPage 1 of 2