Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hana vulnerabilities and exploits
(subscribe to this query)
6.7
CVSSv3
CVE-2019-0357
The administrator of SAP HANA database, prior to 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.
Sap Hana 2.0
Sap Hana 1.0
6.5
CVSSv3
CVE-2021-21474
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and wi...
Sap Hana Database 2.00
Sap Hana Database 1.00
7.5
CVSSv3
CVE-2019-0350
SAP HANA Database, versions 1.0, 2.0, allows an unauthorized malicious user to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service
Sap Hana Database 2.00
Sap Hana Database 1.00
8.3
CVSSv3
CVE-2017-8914
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote malicious users to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.
Sap Hana Xs 2.00
Sap Hana Xs 1.00
7.5
CVSSv3
CVE-2017-8915
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote malicious users to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694.
Sap Hana Xs 2.00
Sap Hana Xs 1.00
5.3
CVSSv3
CVE-2017-16687
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if ...
Sap Hana Database 2.00
Sap Hana Database 1.00
6.1
CVSSv3
CVE-2018-2502
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).
Sap Business One On Hana 9.2
Sap Business One On Hana 9.3
7.5
CVSSv3
CVE-2016-4017
The Data Provisioning Agent (aka DP Agent) in SAP HANA allows remote malicious users to cause a denial of service (process crash) via unspecified vectors, aka SAP Security Note 2262710.
Sap Hana -
7.3
CVSSv3
CVE-2016-4018
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote malicious users to obtain sensitive information, gain privileges, and conduct unspecified other attacks via unspecified vectors, aka SAP Security...
Sap Hana -
NA
CVE-2015-7828
SAP HANA Database 1.00 SPS10 and previous versions do not require authentication, which allows remote malicious users to execute arbitrary code or have unspecified other impact via a TrexNet packet to the (1) fcopydir, (2) fmkdir, (3) frmdir, (4) getenv, (5) dumpenv, (6) fcopy, (...
Sap Hana
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »