Sap Hana vulnerabilities

28 known vulnerabilities affecting sap/hana.

Total CVEs
28
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM12LOW3

Vulnerabilities

Page 2 of 2
CVE-2015-7727MEDIUMCVSS 6.5v1.00.73.00.3891602015-10-15
CVE-2015-7727 [MEDIUM] CWE-89 CVE-2015-7727: Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73 Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors in the (1) trace configuration page or (2) getSqlTraceConfiguration function, aka SAP Security Note 2153898.
nvd
CVE-2015-7725MEDIUMCVSS 6.5v1.00.091.002015-10-15
CVE-2015-7725 [MEDIUM] CWE-89 CVE-2015-7725: Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.09 Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allow remote authenticated users to execute arbitrary SQL commands via the (1) remoteSourceName in the dropCredentials function or unspecified vectors in the (2) setTraceLevelsForXsApps, (3) _modifyUser, or (4) _newUser function, aka SAP
nvd
CVE-2015-7728LOWCVSS 3.5v1.00.73.00.3891602015-10-15
CVE-2015-7728 [LOW] CWE-79 CVE-2015-7728: Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898.
nvd
CVE-2015-7726LOWCVSS 3.5v1.00.091.002015-10-15
CVE-2015-7726 [LOW] CWE-79 CVE-2015-7726: Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allows remote authenticated users to inject arbitrary web script or HTML via the role name, aka SAP Security Note 2153898.
nvd
CVE-2015-3994MEDIUMCVSS 4.0v1.00.73.00.3891602015-05-29
CVE-2015-3994 [MEDIUM] CWE-20 CVE-2015-3994: The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389 The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2109818.
nvd
CVE-2015-3995MEDIUMCVSS 4.0v1.00.73.00.3891602015-05-29
CVE-2015-3995 [MEDIUM] CWE-200 CVE-2015-3995: SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary fil SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565.
nvd
CVE-2015-2072MEDIUMCVSS 4.3v1.00.73.00.389160v1.00.80.00.3918612015-02-27
CVE-2015-2072 [MEDIUM] CWE-79 CVE-2015-2072: Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Deve Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailServ
nvd
CVE-2014-8588HIGHCVSS 7.5v1.00.60.3793712014-11-04
CVE-2014-8588 [HIGH] CWE-89 CVE-2014-8588: SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to e SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
Sap Hana vulnerabilities | cvebase