SAP

Hana Database

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Published 12.09.2023 03:15:12
  • Last modified 21.11.2024 08:19:12

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges...

  • EPSS 0.13%
  • Published 12.09.2023 02:15:12
  • Last modified 21.11.2024 08:19:12

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no abilit...

  • EPSS 0.15%
  • Published 09.02.2021 21:15:13
  • Last modified 21.11.2024 05:48:26

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest c...

  • EPSS 0.16%
  • Published 09.12.2020 17:15:31
  • Last modified 21.11.2024 05:20:22

SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical ...

  • EPSS 0.54%
  • Published 04.11.2019 15:15:11
  • Last modified 21.11.2024 04:16:43

SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service

  • EPSS 0.31%
  • Published 12.06.2018 15:29:00
  • Last modified 21.11.2024 04:03:47

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2....

  • EPSS 0.88%
  • Published 12.12.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the e...