Skip to main content

Vendor/product archive

sap / hana_database CVEs

Beta · best-effort

8 CVEs tagged to sap / hana_database2 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-0492

Published Jan 13, 2026

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-40309

Published Sep 12, 2023

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2023-40308

Published Sep 12, 2023

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-21474

Published Feb 9, 2021

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26834

Published Dec 9, 2020

SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0350

Published Nov 4, 2019

SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-2424

Published Jun 12, 2018

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user in…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-16687

Published Dec 12, 2017

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate v…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1