Hana Database
Vendor:
First CVE: Dec 12, 2017 · Active for 8 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.1
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hana Database over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2017
8 years ago
Most Recent CVE
Jan 13, 2026
194 days ago
CVE Severity & Scoring
Hana Database8 CVEs
38%
50%
13%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None5 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0492HIGH SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. | Jan 13, 2026 | 8.8 | 28 | NO | NO |
CVE-2023-40309CRITICAL SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation o | Sep 12, 2023 | 9.8 | 27 | NO | NO |
CVE-2018-2424HIGH SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user inf | Jun 12, 2018 | 7.5 | 25 | NO | NO |
CVE-2019-0350HIGH SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Deni | Nov 4, 2019 | 7.5 | 23 | NO | NO |
CVE-2023-40308HIGH SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes t | Sep 12, 2023 | 7.5 | 22 | NO | NO |
CVE-2017-16687MEDIUM The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate va | Dec 12, 2017 | 5.3 | 21 | NO | NO |
CVE-2021-21474MEDIUM SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance m | Feb 9, 2021 | 6.5 | 20 | NO | NO |
CVE-2020-26834MEDIUM SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existin | Dec 9, 2020 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Hana Database
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.00 | 6 | 6.8 | 1.1% | 0 | 0 |
| 2.0 | 2 | 8.7 | 0.7% | 0 | 0 |
| 1.00 | 4 | 6.7 | 1.4% | 0 | 0 |