CVE-2021-21484 describes a critical authentication bypass vulnerability in SAP HANA Database version 2.0. This flaw allows attackers to bypass LDAP authentication if the connected LDAP directory server is configured for unauthenticated bind. With a CVSS score of 9.8 (Critical), it presents a severe risk, enabling full compromise of confidentiality, integrity, and availability without requiring any user interaction or prior authentication. Despite its high severity, there is no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:sap:hana:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.