Hana
Vendor:
First CVE: Apr 10, 2014 · Active for 12 years
38
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hana over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2014
12 years ago
Most Recent CVE
Mar 9, 2021
1,966 days ago
CVE Severity & Scoring
Hana38 CVEs
42%
37%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.3%)
Network15 (39.5%)
Unknown21 (55.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (42.1%)
High1 (2.6%)
Unknown21 (55.3%)
User Interaction
None16 (42.1%)
Unknown21 (55.3%)
Required1 (2.6%)
Privileges Required
Low0 (0.0%)
High4 (10.5%)
None13 (34.2%)
Unknown21 (55.3%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1928CRITICAL Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSO | Jan 20, 2016 | 9.8 | 32 | NO | NO |
CVE-2016-6143CRITICAL SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | Apr 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2016-6150CRITICAL The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly | Aug 5, 2016 | 9.8 | 30 | NO | NO |
CVE-2016-1929CRITICAL The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted | Jan 20, 2016 | 9.3 | 30 | NO | NO |
CVE-2015-7986HIGH The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka S | Oct 27, 2015 | 7.5 | 30 | NO | YES |
CVE-2021-21484CRITICAL LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind. | Mar 9, 2021 | 9.8 | 28 | NO | NO |
CVE-2018-2402HIGH In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be | Mar 14, 2018 | 8.4 | 27 | NO | NO |
CVE-2016-6144HIGH The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is conf | Aug 5, 2016 | 8.1 | 27 | NO | NO |
CVE-2015-7828HIGH SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified other impact via a TrexNet packe | Nov 10, 2015 | 10.0 | 27 | NO | NO |
CVE-2018-2465HIGH SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the dat | Sep 11, 2018 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Hana
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.00 | 3 | 6.3 | 1.5% | 0 | 0 |
| 2.0 | 5 | 6.5 | 1.1% | 0 | 0 |
| 1.00.80.00.391861 | 1 | 4.3 | 1.9% | 0 | 0 |
| 1.00.73.00.389160 | 12 | 5.9 | 2.3% | 0 | 0 |
| 1.00.60.379371 | 1 | 7.5 | 1.3% | 0 | 0 |
| 1.00.091.00 | 4 | 5.9 | 1.2% | 0 | 0 |
| 1.00 | 3 | 6.3 | 1.5% | 0 | 0 |
| 1.0 | 4 | 5.7 | 1.1% | 0 | 0 |