Hana

Vendor:

First CVE: Apr 10, 2014 · Active for 12 years

38
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hana over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2014
12 years ago
Most Recent CVE
Mar 9, 2021
1,966 days ago

CVE Severity & Scoring

Hana38 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local2 (5.3%)
Network15 (39.5%)
Unknown21 (55.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (42.1%)
High1 (2.6%)
Unknown21 (55.3%)
User Interaction
None16 (42.1%)
Unknown21 (55.3%)
Required1 (2.6%)
Privileges Required
Low0 (0.0%)
High4 (10.5%)
None13 (34.2%)
Unknown21 (55.3%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSO
Jan 20, 20169.832NONO
SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.
Apr 13, 20179.830NONO
The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly
Aug 5, 20169.830NONO
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted
Jan 20, 20169.330NONO
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka S
Oct 27, 20157.530NOYES
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.
Mar 9, 20219.828NONO
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be
Mar 14, 20188.427NONO
The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is conf
Aug 5, 20168.127NONO
SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified other impact via a TrexNet packe
Nov 10, 201510.027NONO
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the dat
Sep 11, 20187.525NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Hana

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0036.31.5%00
2.056.51.1%00
1.00.80.00.39186114.31.9%00
1.00.73.00.389160125.92.3%00
1.00.60.37937117.51.3%00
1.00.091.0045.91.2%00
1.0036.31.5%00
1.045.71.1%00