Hana Database
8 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Hana Database, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Hana Database CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High3
- Medium3
Latest CVEs
The 8 most recently published vulnerabilities affecting Hana Database.
- CVE-2026-0492Privilege escalation vulnerability in SAP HANA database8.8
- CVE-2023-40309Missing Authorization check in SAP CommonCryptoLib9.8
- CVE-2023-40308Memory Corruption vulnerability in SAP CommonCryptoLib7.5
- CVE-2021-21474SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to t...6.5
- CVE-2020-26834SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer tok...5.4
- CVE-2019-0350SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service7.5
- CVE-2018-2424SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Softwar...9.8
- CVE-2017-16687The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid u...5.3
Product grouping is registry-driven, with AI assist and human review. How it works